Basic network configuration

Prev Next

The following sections describe basic management interface and global network configuration settings.

Management interface settings

The following list describes the management interface configuration settings.

  • IP Version—The appliance has dual-stack support for Internet Protocol version 4 (IPv4) and version 6 (IPv6) on the management interface.

  • DHCP—Dynamic Host Configuration Protocol (DHCP) dynamically distributes network configuration parameters. If DHCP is disabled on the management interface, you must manually configure the IP address, subnet mask, and default gateway or next-hop device.

  • IP Address—The IPv4 or IPv6 address of the management interface. Both types of addresses can be configured. The IPv4 address is enabled by default. You must explicitly enable the IPv6 address.

  • Subnet Mask—The network portion of the IP address. For example, 255.255.255.0 indicates that the first 24 bits of an IPv4 address are used for the network portion of the address.

  • Default Gateway—For an IPv4 address, the IPv4 address of the default router. For an IPv6 address, the IPv6 address of the default router or next-hop device.

  • Autoconf Enabled—When Stateless Address Autoconfiguration (SLAAC) is enabled, an IPv6 address is automatically assigned for the interface. The address is based on an IPv6 prefix learned from router advertisements, combined with an interface identifier based on the MAC address of the interface.

  • Autoconf Route—When this feature is enabled, the system learns a default route from the automatically assigned IPv6 address.

  • Autoconf Privacy—When this feature is enabled, the system generates random host identifiers (known as privacy extensions) to construct the IPv6 address. This provides more security when communicating with remote hosts.

Global network settings

The following list describes global network configuration settings.

  • DNS Servers—Domain Name System (DNS) servers translate domain names to IP addresses for routing. At least one DNS server is required. You can optionally configure a secondary DNS server that is used when the primary server is unavailable or cannot resolve a domain name. You can view a list of DNS servers that will be traversed for DNS resolution, in order, from top to bottom. Only active DNS servers are listed. If neither DNS server can resolve the domain name, an error is displayed.

  • Domain Names—The domain names the DNS servers resolve to IP addresses. You can view a list of domain names in order, from top to bottom.

  • Hostname—The hostname of the appliance (for example, dc-01). You can include the domain (for example, dc-01.acme.com).

  • IPv6—You can enable or disable IPv6 routing on the system, on the management interface, or both. IPv6 must be enabled on the Network Security appliances that are members of a Network Security High Availability (HA) pair. It is enabled automatically by the Central Management System appliance that manages the HA pair.

  • VPN—You can enable or disable virtual private networking (VPN) on the system. When VPN is enabled, the appliance can connect to Managed Defense over the Internet using a secure SSL VPN connection. VPN requires a valid MD_ACCESS license on the appliance. VPN requires IPv6 routing, so IPv6 must be enabled on the system before you can enable VPN. For more information, see the Managed Defense Quick Start Guide.

Prerequisites
  • Operator or Admin access