Check Point CloudGuard Connect
配置>云服务>检查点CloudGuard Connect
Check Point CloudGuard Connect提供网络和云安全性,并在编目叠加层中定义的策略。这Check Point CloudGuard ConnectTAB具有以下字段。
| 场地 | Description |
|---|---|
| Subscription | 您要与检查点连接的设备名称。 |
| Interface Labels | 您要与检查点连接的接口名称。 |
| 隧道设置 | Defines the tunnels associated with Orchestrator and Check Point. |
| LAN Subnets | Subnets configured on the LAN side associated with Check Point. |
Before you begin to configure Check Point CloudGuard Connect, you need to create a Check Point account. Visit the following link to make an account:https://portal.checkpoint.com.
After you create an account, you will need to create an API Key.
Subscription
After you complete the steps in the above URL to create your Check Point account, navigate to theCheck Point CloudGuard Connecttab in Orchestrator.
Select theSubscription选项卡以开始检查点。
Enter your客户端IDand the密钥创建检查点帐户时收到的。
SelectSaveafter you finish entering the information in the table below. The连接状态should appear at the top of theSubscriptionwindow.
Interface Labels
Select theInterface Labels标签。这Build Tunnels Using These Interfacesopens.
将要使用的接口标签拖到首选接口标签顺序column.
SelectSave。
隧道设置
这隧道设置tab helps you define the tunnels associated with Check Point and EdgeConnect. Use the Check Point default values for theGeneral,,,,IKE, 和ipsec隧道设置。
NOTE:您还可以配置特定的常规,IKE和IPSEC隧道设置。设置将自动生成;但是,如果您选择这样做,则可以进行修改。要返回默认设置,请选择Use Defaulton any of the tunnel windows.
LAN Subnets
You can select the LAN subnets for a given appliance to associate with your Check Point integration. By default, LAN subnets are configured on the部署标签。您还可以添加,导入CSV文件或导出配置的子网的CSV文件。
Enabling Check Point CloudGuard Connect
When you have completed configuration, you need to enable the Check Point service.
Navigate to the业务意图覆盖tab in Orchestrator.
Go to the互联网和云服务的突破流量。
选择破坏流量以检查点的覆盖层。
拖Check Point CloudGuard Connectfrom the可用的政策列到Preferred Policy Ordercolumn.
Verification
Navigate to theCheck Point CloudGuard Connecttab in Orchestrator to verify successful deployment underSite Status。You can also verify successful deployment on the隧道标签。
进口and Export Subnets
进口使您能够将逗号分隔值(CSV)文件导入编排中使用的一对电器。导入之前,必须删除标题行并将文件保存在计算机上。完成以下步骤开始您的导入。
SelectChoose File。
Locate the file you want to import on your desktop.
SelectOpen。
选择导入。乐队生成CSV文件。下表表示导出的CSV文件中的字段。
Appliance Configured Subnets <设备主机名> NOTE:导入之前,应从文件中删除标题和双引号。
CAUTION:此导入覆盖先前配置的导入。