If NAT is applied to communications between the NGFW Engine and some other component that contacts the NGFW Engine, define the Default contact address for the single NGFW Engine or the Cluster Virtual IP Address (CVI). You can also define location-specific contact addresses.
For more details about the product and how to configure features, click Help or press F1.
Steps
-
Select Configuration.
-
Right-click an engine element and select
Edit <element type>.
-
In the
General pane, select the
Location for this element.
-
Browse to
Interfaces in the navigation pane on the left.
-
In the tree view, expand the tree and double-click the Cluster Virtual IP Address (CVI) or the IP address for which you want to define a contact address.
On Firewall Clusters, the CVI contact address is used for VPNs and NDI contact addresses are used for other system communications.
-
In the
IP Address Properties dialog box, define the Default contact address. The Default contact address is used by default whenever a component that belongs to another Location connects to this interface.
- If the interface has a static Default contact address, enter the Default contact address in the
Default field.
- If the interface has a dynamic Default contact address, select
Dynamic (next to the
Default field) before entering the Default contact address.
-
If components from some Locations cannot use the Default contact address to connect to the interface, click
Exceptions to define Location-specific contact addresses.
-
Click
Add and select the Location.
-
Click the
Contact Address column and enter the IP address that the components in this Location use when they contact the interface or select
Dynamic if the interface has a dynamic contact address.
Note: Elements that belong to the same Location element always use the primary IP address (defined in the element’s properties) when contacting each other. Elements that do not belong to a specific Location belong to the Default Location.
-
Click
OK to close the
Exceptions dialog box.
-
Click
OK to close the
IP Address Properties dialog box.