Configuring Internet Connection Types
You must configure a primary Internet connection, and you can configure a secondary one. When High Availability is activated, if there is a failover on the primary Internet connection, then the Small Office Appliance starts to use the secondary Internet connection.
These are the Internet connections:
-
Static IP - A fixed (non-dynamic) IP address.
Configuring a Static Internet Connection
You can configure an Internet connection with a static IP address.
-
From the Devices window, double-click the Small Office Appliance network object.
The Security Gateway
Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. window opens.
-
Select the Internet tab.
-
Select Use the following settings. The Internet connection settings open.
-
Configure the primary Internet connection type:
-
Select Enable Primary Internet Connection.
-
Select whether the primary Internet connection is on the WAN or DMZ.
-
From Connection Type, select Static IP.
-
-
Click Configure.
The Primary Internet Configuration window for the Static IP Internet connection type opens.
-
In the IP Settings section, enter these IP address parameters:
-
IP Address
-
Subnet Mask
-
Default Gateway
-
-
In the DNS section, enter the IP addresses for the DNS servers.
-
In the WAN Port Settings section, enter these interface settings:
-
To configure the MTU (Maximum Transmission Unit) for the Internet connection, enter the new MTU value.
Note - For a DMZ interface, the MTU value is applied to all LAN ports.
-
To assign a MAC address to the Internet connection, select Override MAC Address and enter the MAC address.
-
To configure the bandwidth for the Internet connection, select the appropriate option from Link speed/Duplex.
-
-
From the Advanced section, you can select Use ICMP to monitor connection status (see Configuring ICMP).
-
Click OK.
-
-
DHCP - Dynamic Host Configuration Protocol (DHCP) automatically issues IP addresses within a specified range to devices on a network.
Configuring a DHCP Internet Connection
You can configure an Internet connection that uses DHCP to automatically assign IP addresses.
-
From the Devices window, double-click the Small Office Appliance network object.
The Security Gateway window opens.
-
Select the Internet tab.
-
Select Use the following settings. The Internet connection settings open.
-
Configure the primary Internet connection type:
-
Select Enable Primary Internet Connection.
-
Select whether the primary Internet connection is on the WAN or DMZ.
-
From Connection Type, select Obtain IP Address Automatically (DHCP).
-
-
Click Configure.
The Primary Internet Configuration window for the DHCP Internet connection type opens.
-
In the WAN Port Settings section, enter these interface settings:
-
To configure the MTU (Maximum Transmission Unit) for the Internet connection, enter the new MTU value.
Note - For a DMZ interface, the MTU value is applied to all LAN ports. .
-
To assign a MAC address to the Internet connection, select Override MAC Address and enter the MAC address.
-
To configure the bandwidth for the Internet connection, select the appropriate option from Link speed/Duplex.
-
-
From the Advanced section, you can select Use ICMP to monitor connection status (see Configuring ICMP).
-
Click OK.
-
-
PPPoE - A network protocol for encapsulating Point-to-Point Protocol (PPP) frames inside Ethernet frames. It is used mainly with DSL services where individual users connect to the DSL modem over Ethernet and in plain Metro Ethernet networks
Note - It is not possible to configure internet connection over DSL for 1100, 1430, 1450 appliances using SmartProvisioning
Check Point Software Blade on a Management Server (the actual name is "Provisioning") that manages large-scale deployments of Check Point Security Gateways using configuration profiles. Synonyms: Large-Scale Management, SmartLSM, LSM..
Configuring a PPPoE Internet Connection
You can configure an Internet connection that uses PPPoE protocol.
Basic Configuration
-
From the Devices window, double-click the Small Office Appliance network object.
The Security Gateway window opens.
-
Select the Internet tab.
-
Select Use the following settings. The Internet connection settings open.
-
Configure the primary Internet connection type:
-
Select Enable Primary Internet Connection.
-
Select whether the primary Internet connection is on the WAN or DMZ.
-
From Connection Type, select Point-to-Point Protocol over Ethernet (PPPoE).
-
-
Click Configure.
The General tab of the Primary Internet Configuration window for the PPPoE Internet connection type opens.
-
Enter these settings for your Internet Service Provider:
-
User Name
-
Password
-
-
In the WAN Port Settings section, enter these interface settings:
-
To configure the MTU (Maximum Transmission Unit) for the Internet connection, enter the new MTU value.
Note - For a DMZ interface, the MTU value is applied to all LAN ports.
-
To assign a MAC address to the Internet connection, select Override MAC Address and enter the MAC address.
-
To configure the bandwidth for the Internet connection, select the appropriate option from Link speed/Duplex.
-
-
Click OK.
PPPoE Advanced Settings
You can configure the advanced settings for a PPPoE Internet connection. The advanced settings allow you to configure:
-
IP settings for the tunnel
-
How the Internet connection is started and maintained
-
From the Primary Internet Configuration window for PPPoE, select Advanced.
The Advanced PPPoE window opens.
-
In the Local Tunnel IP Assignment section, enter these settings for the PPPoE tunnel:
-
Obtain IP Address Automatically - The IP address for the PPPoE tunnel is automatically configured (default setting).
-
Use the Following IP Address - Enter the static IP address that is used for the PPPoE tunnel.
-
-
In the Connection Method section, configure how the Small Office Appliance uses the PPPoE Internet connection:
-
Auto Connect - The Small Office Appliance automatically establishes a PPPoE connection to the Internet.
-
Connect on Demand - The Small Office Appliance Gateway establishes a PPPoE connection to the Internet when required.
-
Disconnect Idle Time - Enter the number of maximum number of idle minutes before the PPPoE Internet connection is disconnected.
-
-
In the Monitor Connections section, enter the PPPoE Echo requests settings:
-
Monitor Connection Status Every - Enter how often, in seconds, that PPPoE Echo requests are sent to the server.
-
Assume Connection is Down After - Enter the maximum number of failed PPPoE Echo requests before the PPPoE server is considered down.
-
From the Advanced section, you can select Use ICMP to monitor connection status (see Configuring ICMP).
-
-
Click OK.
-
-
PPTP - The Point-to-Point Tunneling Protocol (PPTP) is a method for implementation of virtual private networks. PPTP uses a control channel over TCP and a GRE tunnel operating to encapsulate PPP packets.
-
L2TP - Layer 2 Tunneling Protocol (L2TP) is a tunneling protocol used to support virtual private networks (VPNs). It does not provide any encryption or confidentiality by itself. It relies on an encryption protocol that it passes within the tunnel to provide privacy.
-
From the Devices window, double-click the Small Office Appliance network object.
The Security Gateway window opens.
-
Select the Internet tab.
-
Select Use the following settings. The Internet connection settings open.
-
Configure the primary Internet connection type:
-
Select Enable Primary Internet Connection.
-
Select whether the primary Internet connection is on the WAN or DMZ.
-
From Connection Type, select Point-to-Point Tunneling Protocol over Ethernet (PPTP) or Layer 2 Tunneling Protocol (L2TP).
-
-
Click Configure.
The General tab of the Primary Internet Configuration window for the Internet connection type opens.
-
Enter these settings for your Internet Service Provider:
-
Server Host Name or IP Address
-
ISP Login User Name
-
ISP Login Password
-
-
In the WAN Port Settings section, enter these interface settings:
-
To configure the MTU (Maximum Transmission Unit) for the Internet connection, enter the new MTU value.
Note - For a DMZ interface, the MTU value is applied to all LAN ports. .
-
To assign a MAC address to the Internet connection, select Override MAC Address and enter the MAC address.
-
To configure the bandwidth for the Internet connection, select the appropriate option from Link speed/Duplex.
-
-
Click OK.
-
IP settings for the tunnel and the WAN
-
How the Internet connection is started and maintained
-
From the Primary Internet Configuration window for PPTP or L2TP, select Advanced.
The Advanced settings open.
-
In the Local Tunnel IP Assignment section, enter the settings for the tunnel:
-
Obtain IP Address Automatically - The IP address for the tunnel is automatically configured (default setting).
-
Use the Following IP Address - Enter the static IP address that is used for the tunnel.
-
-
In the WAN IP Assignment section, enter the IP address settings for the WAN:
-
Obtain IP Address Automatically - The IP address for the WAN is automatically configured (default setting).
-
Use the Following IP Address - Configure these settings for the WAN IP address:
-
IP Address
-
Subnet Mask
-
Default Gateway
-
-
-
In the Connection Method section, configure how Small Office Appliance uses the PPTP or L2TP Internet connection:
-
Auto Connect - Small Office Appliance automatically establishes a PPTP or L2TP connection to the Internet.
-
Connect on Demand - Small Office Appliance establishes a PPTP or L2TP connection to the Internet when required.
-
Disconnect Idle Time - Enter the number of maximum number of idle minutes before the PPTP or L2TP Internet connection is disconnected.
-
-
In the Monitor Connections section, enter the Echo request settings:
-
Monitor Connection Status Every - Enter how often (in seconds) that Echo requests are sent to the server.
-
Assume Connection is Down After - Enter the maximum number of failed Echo requests before the server is considered down.
-
From the Advanced section, you can select Use ICMP to monitor connection status (see Configuring ICMP).
-
-
Click OK.


You can configure the advanced settings for a PPTP or L2TP Internet connection. The advanced settings allow you to configure:
When you have enabled both Internet connections, you can configure High Availability to revert back to the primary Internet connection.
You can configure the ICMP (Internet Control Message Protocol) settings for the Internet connection. You can specify servers that receive ICMP requests to monitor the status of the Internet connection. If you enabled High Availability, the Small Office Appliance can activate the other Internet connection when necessary.

-
From the Devices window, double-click the Small Office Appliance.
The Security Gateway window opens.
-
Select the Internet tab.
-
From the required Internet connection, click Configure.
The Internet Configuration window is opens.
-
From the Advanced section or tab, select Use ICMP to monitor connection status.
-
Click Configure.
The ICMP Settings window opens.
-
To monitor a server:
-
Click Add.
-
Enter the host name or IP address of the server.
-
Repeat these steps for all the servers that are monitored.
-
Select Send ICMP requests to the following servers.
-
-
To monitor the default gateway, select Send ICMP requests to default gateway.
-
Enter these ICMP connection monitoring settings:
-
Interval Between - Enter the number of seconds between each ICMP request.
-
Failover After - Enter the maximum number of failed ICMP requests. When High Availability is active, after an ICMP failover the other Internet connection becomes active.
-
Resume Requests After - Enter the number of seconds after an ICMP failover that ICMP requests are resumed.
-
-
Click OK.