213455-L, October 2005
245
C
HAPTER
9
Basic system management
This chapter explains how to access system management features on the Nortel Switched
Firewall. Management access is required for collecting system information, configuring
system parameters beyond initial setup, establishing security policies, and monitoring policy
effectiveness.
Management tools
The Nortel Switched Firewall provides the following system management tools:
The Command Line Interface (CLI)
The CLI offers a simple, text-based menu system for collecting system information and
configuring system parameters. Use of the CLI is required for initial setup of the system.
The CLI can be accessed locally at any Firewall or remotely through Telnet or Secure
Shell (SSH) once access has been granted (see
Defining the remote access list on page
252
).
For additional details, see
The Command Line Interface on page 251
.
The Browser-Based Interface (BBI)
The BBI allows management through your web browser. BBI access must be enabled
through the CLI and Check Point SmartDashboard after initial setup is complete. Once
enabled, the BBI provides a richly featured graphical user interface that makes routine
configuration and data collection easy.
In previous releases, the BBI accessed the firewall through the SSI interface only. In NSF
2.3.1 and later versions the SSI interface is separated from the Check Point policies and
accessing the firewall host IP address compromises security. Instead of using the firewall
gateway, you can access the firewall using the VRRP virtual IP address. When you access
the firewall using the VRRP virtual IP address you can control access to the firewall by
adding user-defined Check Point policies.