Manual configuration means that there will be a direct connection to the ISP and all relevant IP
addresses for the connecting interface are fixed values that will be entered into cOS Core
manually.
Note: The interface DHCP option should be disabled
For static configuration of the Internet connection, the DHCP option must be disabled in
the properties of the Ethernet interface that will connect to the ISP. In this case,
WAN2
.
The initial step is to set up a number of IPv4 address objects in the cOS Core
Address Book
. Let us
assume that the interface used for Internet connection is to be
WAN2
and that the static public
IPv4 address for this interface is to be
203.0.113.35
, the ISP's gateway IPv4 address is
203.0.113.1
,
and the network to which they both belong is
203.0.113.0/24
.
Now, add the gateway
IP4 Address
object using the address book name
wan_gw
and assign it the
IPv4 address
203.0.113.1
. The ISP's gateway is the first router hop towards the public Internet
from the Clavister Next Generation Firewall. Go to Objects > Address Book in the Web Interface.
The current contents of the address book will be listed and will contain a number of predefined
objects automatically created by cOS Core after it scans the interfaces for the first time. The
screenshot below shows the initial address book for the NetWall 100 Series.
Note: The all-nets address
The IPv4 address object
all-nets
is a wildcard address that should never be changed and
can be used in many types of cOS Core rules to refer to any IPv4 address or network
range.
All the Ethernet interface related address objects are gathered together in an
address book folder
called
InterfaceAddresses
. By clicking on this folder, it will be opened and the individual address
objects it contains can be viewed.
On initial startup, two IPv4 address objects are created automatically for each Ethernet interface
detected by cOS Core. One IPv4 address object is named by combining the physical interface
name with the suffix "
_ip
" and this is used for the IPv4 address assigned to that interface. The
other address object is named by combining the interface name with the suffix "
_net
" and this is
the network to which the interface belongs.
Tip: Creating address book folders
New folders can be created when needed and provide a convenient way to group
together related IP address objects. The folder name can be chosen to indicate the
folder's contents.
Chapter 4: cOS Core Configuration
47