Network Objects and Groups
Starting from R81.10.15, the Users & Objects view > Network Resources section > Network Objects is a unified objects and groups page to create and manage network objects and groups. This replaces the separate Managing Network Objects and Managing Network Object Groups pages used in version R81.10.10 and lower.
On this page you can add, edit, and delete network objects and groups.
|
Important - You can create a maximum of 1000 objects in total. For example, 500 host objects, 300 network objects, and 200 Domain Name objects. |
For each object or group, the columns in the table display the name, type, information (for example, IP address or range of an object) and starting from R81.10.05, where it is used, for example the specific rules in the Access Policy.
|
Note - Starting in version R81.10.17, the "Where in use" feature is turned off by default. To enable this feature, go to Advanced Settings > WebUI settings and customizations - Enable where in use and change the value to |
Use the Search field at the upper right corner of the page to search for an object. The table display highlights the group in which the object is found.
For each group, when you hover over one of the objects within the group, you can see specific information about the object such as its type, IP addresses and in which group it is used.
The most common use for network objects is to define a security policy and exceptions to it. These objects can be used as hosts for the internal DNS service and their IP addresses can be configured as fixed for the internal DHCP service.
You can make a new access policy rule in the Access Policy > Firewall > Policy page and use one of the network objects or groups as the source or destination. The Manual Rules table on the Access Policy page displays the objects in the relevant rule. The Where Used column in the Network Objects table shows also displays the access policy rule you just created.
To create a new network object on the Network Objects page:
-
Click New and select Network Object.
-
In the New Network Object window, select Type:
-
Single IP - Represents a device with a single IP address (host object). Select or clear these options as necessary:
-
Allow DNS server to resolve this object name - When the gateway is the DNS server for your internal networks, the name of the server / network object is translated to its IP address.
-
Exclude from DHCP service - The internal DHCP service does not distribute the configured IP address of this server / network object to anyone.
-
Reserve IP address for DHCP service for MAC - The internal DHCP service distributes the configured IP address only to this server / network object based on its MAC address.
-
Enter the MAC address - This is required for IP reservation. When you create the object from the Assets page, the MAC address is detected automatically.
-
-
IP Range - Represents a range of IP addresses. Enter the Start IP and End IP. Select or clear this option as necessary:
Exclude from DHCP service - The internal DHCP service does not distribute the configured IP range to anyone.
-
Device - Enter the MAC address. Optional: Select Bypass host with this MAC by SSL Inspection.
If you select to Use custom hardware name, enter the Device type, Hardware, and Operating system
-
-
Enter the Name and IP address.
-
Depending on the object type, you may need to configure additional fields.
-
Click Save.
To create a new Network Object Group on the Network Objects page:
-
Click New and select Network Object Group.
-
In the New Network Object Group window, enter a Name for the group.
-
Optional: Add a comment.
-
Select existing objects to add to this group or click New to create a new object.
-
Click Save.
To use an object in an Access Policy rule:
-
In WebUI, click the Access Policy view > Firewall section > Policy page.
-
Add a new rule or edit an existing rule.
-
In the Source column or the Destination column, select the object.
-
Configure other columns in this rule.
-
Click Save.
In Centrally Managed appliances, objects are created in SmartConsole Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on..
Creating and managing network objects in the appliance WebUI is supported for interfaces and other networking services which are not configurable in SmartConsole.
Creating a Security Gateway object in SmartConsole

-
Log in to SmartConsole.
-
In the Gateways & Servers view, on the top toolbar select New > Gateway.
-
Click Wizard Mode.
-
On the General Properties page:
-
In the Gateway name field, enter the desired name for this Security Gateway
A dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. object.
-
In the Gateway platform field, select the correct model of your Quantum Spark appliance
-
In the Version field, select (if the field allows) the correct version family on your Quantum Spark appliance
-
In the Platform Type field, select (if the field allows) the correct model type of your Quantum Spark appliance
-
In the Gateway IP address section, select the applicable option (for a Static IP address, configure the IPv4 address of the WAN interface).
-
Click Next.
-
-
On the Trusted Communication page:
-
Select the application options and configure the one-time password.
You enter this one-time password later in the WebUI of the Quantum Spark appliance.
If you selected to initialize the trusted communication in the real time, then the Certificate state field must show "Trust established".
-
Click Next.
-
-
On the Blade Activation page:
-
Select the required Software Blades.
-
Click Next.
-
-
On the Blade Configuration page:
-
Configure the required settings.
-
Click Next.
-
-
On the Installation Wizard Completion page:
-
Review the configuration summary.
If you select Edit gateway properties for further configuration, then after the Wizard creates the Security Gateway, it opens the object for further configuration.
-
Click Finish.
-
-
On your Quantum Spark Appliance, connect to the Management Server
A Check Point Security Management Server or a Multi-Domain Security Management Server..
-
In SmartConsole, open this Security Gateway object.
-
On the Topology page:
-
In the Security Blades section, select the applicable option.
-
In the Topology Table, you can get the interface settings from the Quantum Spark Appliance and override the interface settings.
-
-
On the General Properties page, enable and configure the required Software Blades.
-
Configure the other required settings in this Security Gateway object.
-
Click OK.
-
Configure the required Access Control Policy and Threat Prevention Policy.
-
Install the Access Control Policy and Threat Prevention Policy on the Security Gateway object.

-
Log in to SmartConsole.
-
In the Gateways & Servers view, on the top toolbar select New > Gateway.
-
Click Classic Mode.
-
Starting from R82, this popup appears:
Threat Prevention blades are now active by default. To see the active blades, refer to General > Threat Prevention tab or sk182108.
Click OK.
-
In the Name field, enter the desired object name.
In the IPv4 Address field, enter the IP address of the WAN interface.
-
In the Secure Internal Communication section, click the Communication button.
-
In the Platform field, select Small Office Appliance.
-
Select the application options and configure the one-time password
You enter this one-time password later in the WebUI of the Quantum Spark Appliance.
If you selected to initialize the trusted communication in the real time, then the Certificate state field must show "Trust established."
-
If in Step 8 you initialized the trusted communication in real time, then the fields Hardware, Version, and Type are populated automatically.
If in Step 8 you did not initialize the trusted communication in real time, then in the fields Hardware, Version, and Type you must select the correct values for your Quantum Spark Appliance.
-
If in Step 8 you did not initialize the trusted communication in real time, then:
-
Click OK in this Security Gateway Gateway object.
-
Publish the session in SmartConsole.
-
On your Quantum Spark Appliance, connect to the Management Server.
-
-
In SmartConsole, open this Security Gateway object.
-
Configure the other required settings in this Security Gateway object.
-
On the Topology page:
-
In the Security Blades section, select the applicable option.
-
In the Topology Table, you can get the interface settings from the Quantum Spark Appliance and override the interface settings.
-
-
On the General Properties page, enable and configure the required Software Blades.
-
Configure the other require settings in this Security Gateway object.
-
Click OK.
-
Configure the required Access Control Policy and Threat Prevention Policy.
-
Install the Access Control Policy and Threat Prevention Policy on the Security Gateway object.
Creating a Cluster object in SmartConsole

-
Log in to SmartConsole.
-
In the Gateways & Servers view, on the top toolbar select New > Cluster > Small Office Cluster.
-
Click Classic Mode.
-
Starting in R82, this popup appears:
Threat Prevention blades are now active by default. To see the active blades, refer to General > Threat Prevention tab or sk182108.
Click OK.
-
On the General Properties page:
-
In the Name field, enter the desired object name.
-
In the IPv4 Address field, enter the Cluster
Two Quantum Spark Appliances connected to each other for High Availability. Virtual IPv4 address that is assigned to the WAN interface.
-
In the Hardware field, select the correct model of your Quantum Spark appliances (both appliances must be the same model).
-
In the Version field, select (if this field allows) the correct firmware family on your Quantum Spark appliances.
-
In the Type field, select (if this field allows) the correct model type of your Quantum Spark appliances.
-
Enable and configure the required Software Blades.
-
-
On the Cluster Members page:
-
Click Add > New Cluster Member.
-
In the Name field, enter the desired object name:
-
In the IPv4 Address field, enter the IPv4 address that is assigned to the WAN interface
-
Optional: In the IPv6 Address field, enter the IPv6 address that is assigned to the WAN interface
-
Click Communication.
-
-
Enter a one-time password:
-
Click Initialize.
-
The Trust state field must show "Trust established".
-
Click Close.
-
-
Repeat the above steps to add the second Quantum Spark Cluster Member
A Security Gateway that is part of a cluster..
-
-
On the Topology page:
-
In the Security Blades section, select the applicable option.
-
In the Topology Table, click Edit Topology and configure the required settings - Network Object, Cluster Virtual IP addresses , Subnet masks, and Interface properties.
-
-
Configure the other require settings in this Security Gateway object.
-
Click OK.
-
Configure the required Access Control Policy and Threat Prevention Policy.
-
Install the Access Control Policy and Threat Prevention Policy on the cluster object.
Editing, Deleting and Filtering Network Objects

-
Select a network object from the list.
-
Click Edit.
-
Make the necessary changes.
-
Click Save.

-
Select the network object from the list.
-
Click Delete.
-
Click Yes in the confirmation message.

-
In the Type to filter box, enter the name of the network object or part of it.
-
As you enter text, the list is filtered and shows matching results.