Configuring the Local Network
Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.40 Locally Managed Administration Guide | 79
To enable WAN as LAN:
1. Go to Device > Advanced Settings and select OS advanced settings - Enable LAN on WAN.
2. Click Edit to change the value to true.
The Device > Local Network page now shows WAN ports included in the list of LAN and DMZ (local
interfaces, switches, bridges, bonds and VLANs).
n
When used for WAN networks, the interface name of the WAN port is WAN.
n
When used for LAN networks, the interface name of the WAN port is LANW.
Configuration parameters for WAN as LAN are similar to DMZ.
Monitor Mode
Security Gateways can monitor traffic from a Mirror Port or Span Port on a switch.
With Monitor Mode, the appliance uses Automatic Learning or user-defined networks to identify internal and
external traffic, and to enforce policy.
Automatic Learning - The appliance automatically recognizes external networks by identifying the default
gateway's network from requests to the Internet (specifically, requests to Google). The rest of the networks
are considered internal.
User-Defined Networks - You can manually define internal networks. If a network is not defined as internal,
it is considered external.
In both Automatic Learning and user-defined networks:
n
Traffic to internal hosts is inspected by the Incoming/Internal/VPN Rule Base.
n
Traffic to external hosts is inspected by the Outgoing Rule Base.
n
Threat prevention's default configuration is optimized to inspect suspicious traffic from external hosts
to internal hosts.
To configure monitor mode in the WebUI:
1. Go to Device > Local Network.
2. Select an interface and double-click.
The Edit window opens in the Configuration tab.
3. In the Assigned To drop-down menu, select Monitor Mode.
The Manually define internal networks checkbox shows.
4. To use Automatic Learning, do not select Manually define internal networks and click Apply.
5. To use your own network definitions, select Manually define internal networks.
The network definition features and table show.
6. Click New.
7. Enter the network IP address.
8. Enter the subnet. An internal network can be a 255.255.255.255 subnet, for one host.