EasyManua.ls Logo

Quantum CHECK POINT SPARK 1800 Series - User Manual

Quantum CHECK POINT SPARK 1800 Series
300 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Loading...
Models: V-80, V-80W, V-81, V-81W, V-81WL, V-81WD, V-81R, V-81WLR, V-82, V-83 [Classification: Protected]
12 April2022
QUANTUM SPARK 1500,
1600 AND 1800
APPLIANCE SERIES
R80.20.40
Locally Managed
Administration Guide

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Quantum CHECK POINT SPARK 1800 Series and is the answer not in the manual?

Quantum CHECK POINT SPARK 1800 Series Specifications

General IconGeneral
BrandQuantum
ModelCHECK POINT SPARK 1800 Series
CategoryNetwork Hardware
LanguageEnglish

Summary

Getting Started

Installing the appliance and connecting the cables

Covers the initial physical setup, including connecting all necessary cables to the appliance.

Configuring VPN

Explains how to configure various VPN scenarios, including remote access and site-to-site VPNs.

Setting up the Quantum Spark Appliance

Deploying from a USB Drive or SD Card

Deploying the Configuration File - Initial Configuration

Describes deploying a configuration file via USB for the initial setup of the appliance.

Configuring VPN

Configuring Remote Access VPN

Details how to set up remote access VPNs using various client options.

Configuring Site to Site VPN with a Preshared Secret

Explains the steps to configure a site-to-site VPN using a preshared secret for authentication.

Configuring Site to Site VPN with a Certificate

Describes how to set up site-to-site VPN using certificates for authentication.

Managing Clusters

Configuring a Cluster

Provides instructions on how to configure a cluster for redundancy and high availability.

Upgrading a Cluster

Explains how to upgrade cluster members while maintaining network connectivity.

Controlling and Monitoring Software Blades

Setting the Management Mode

To set the management type

Describes how to set the appliance management type to locally or centrally managed.

Configuring Cloud Services

To connect the appliance to Cloud Services

Provides steps to connect the appliance to Cloud Services for remote management.

Managing Licenses

If you have Internet connectivity configured

Instructions for activating appliance licenses when internet connectivity is configured.

If your appliance is not registered

Steps for registering the appliance and activating its license.

Managing the Device

Configuring Internet Connectivity

Guides on configuring single or multiple internet connections, including HA and Load Balancing.

Configuring Wireless Network

Configuring the Local Network

Configuring a Hotspot

Guides on configuring hotspot features like guest access, portal appearance, and exceptions.

Configuring the Routing Table

Details how to manage the Firewall Rule Base, including creating, editing, and disabling rules.

Configuring MAC Filtering

Explains how to manage an allowlist of MAC addresses for LAN access control.

Configuring the DNS Server

Backup, Restore, Upgrade, and Other System Operations

To backup appliance settings

Guides on backing up appliance settings, including security policy and licenses.

To restore a backed up configuration

Instructions for restoring appliance settings from a previously saved backup file.

Using the Software Upgrade Wizard

Details on using the Software Upgrade Wizard for firmware updates.

Configuring Local and Remote System Administrators

To create a local administrator

Steps for creating new local administrators with specified permissions.

To allow access for administrators defined in a remote RADIUS server

Grants access to administrators defined on a remote RADIUS server.

Configuring Administrator Access

To allow administrator access from specified IP addresses

Allows administrator access only from specified IP addresses or networks.

Configuring DDNS and Access Service

Reach My Device

Describes the service for remotely connecting to the appliance via WebUI or CLI.

Configuring High Availability

To create a cluster

Step-by-step guide to creating a cluster using the New Cluster Wizard.

Advanced Settings

VPN Remote Access Attributes

Attributes for VPN Remote Access, covering traffic handling, authentication, and Office Mode.

VPN Site to Site Global Setting Attributes

Global settings for VPN Site to Site, including NAT traversal and administrative notifications.

Managing the Access Policy

Configuring the Firewall Access Policy and Blade

Sets the default Access Policy control level and configures security requirements for traffic.

Firewall Policy

Defines the default access policy mode: Strict, Standard, or Off.

Application & URL Filtering

Defines how to handle applications and URL categories for traffic to the Internet.

User Awareness

Enables and configures User Awareness for access control and user-based logging.

Working with the Firewall Access Policy

Configuring Access Rules

Provides steps to create new manually defined access rules for the firewall.

Updatable Objects

Defining Firewall Servers

To create a new object

Steps to create a new server object using the New Server Wizard.

Defining NAT Control

To configure a server that is routable from the Internet (server with NAT)

Configures servers accessible from the Internet, including port forwarding and static NAT.

Inspecting VoIP Traffic

To configure VoIP inspection in the WebUI

Provides steps to configure VoIP inspection, including SIP provider and on-premise device settings.

Working with User Awareness

Configuring the QoS Blade

QoS

Allows activating QoS, defining default policy, and adding manual rules for bandwidth control.

QoS default policy

Options for default QoS policy: low latency priority, bandwidth guarantee, and limiting consuming applications.

Working with QoS Policy

To create a QoS rule

Steps to create a QoS rule, including setting guarantee, limit, weight, and tracking.

SSL Inspection Policy

SSL Inspection

Enables and configures SSL inspection, allowing blades to inspect encrypted traffic.

Deploying SSL Inspection

Steps to deploy SSL inspection, including downloading and installing the CA certificate.

SSL Inspection Bypass Policy

Allows configuring exceptions to bypass SSL inspection for specific traffic.

SSL Inspection Exceptions

To add bypass exceptions

Defines manual rules to configure exceptions for bypassing SSL inspection.

Managing Threat Prevention

Configuring Threat Prevention Blade Control

Allows activation of IPS, Anti-Virus, Anti-Bot, and Threat Emulation blades.

To create a custom policy for Threat Prevention

Guides on creating a custom policy by selecting tracking, activation, severity, and performance impact.

Configuring Threat Prevention Policy Exceptions

Threat Prevention Exceptions

Configures exception rules for traffic that IPS and malware engines do not inspect.

Threat Prevention - Infinity SOC

Enables Infinity SOC feature for effective threat prevention, detection, and response.

Viewing Infected Devices

Advanced Threat Prevention Engine Settings

IPS

Configures advanced settings for IPS, including bypass mode and detect-only mode.

Threat Emulation

To configure the Threat Emulation settings

Configures Threat Emulation settings for incoming and outgoing files across different protocols.

Configuring the Anti-Spam Blade Control

To configure the Anti-Spam Policy

Configures the spam filter based on sender address and email content.

Configuring Anti-Spam Exceptions

Managing VPN

Configuring the Remote Access Blade

Establishes secure encrypted connections for remote access via VPN.

To manage SSL VPN bookmarks

Allows creation, management, and configuration of SSL VPN bookmarks.

Configuring Remote Access Users

To add a new local user with remote access permissions

Steps to add new local users and configure their remote access permissions.

To add remote access permissions to an existing Active Directory group

Grants remote access permissions to existing Active Directory groups.

To add remote access permissions for users defined in the RADIUS group

Configures remote access permissions for users defined in a RADIUS group.

Two-Factor Authentication

Adds an extra layer of security to prevent unauthorized access using multi-factor authentication.

Configuring Remote Access Authentication Servers

Configuring Advanced Remote Access Options

Office Mode

Configures Office Mode network settings for remote VPN clients accessing organization resources.

To route all traffic from VPN remote access clients through the gateway

Enables routing all client traffic through the gateway, enforcing outgoing access policy.

Configuring the Site to Site VPN Blade

To enable or disable the VPN Site to Site blade

Activates or deactivates the Site to Site VPN blade for creating VPN tunnels with remote sites.

Configuring VPN Sites

To add a new VPN site

Steps to add a new VPN site, configuring remote site details, encryption, and advanced options.

Configuring Advanced Site to Site Settings

Configuring the Appliance Interfaces

Configures appliance interfaces for VPN traffic, including link selection and source IP.

Managing Installed Certificates

To create a new certificate to be signed by a CA

Steps to create a new signing request for a certificate to be signed by a CA.

Managing Users and Objects

To configure User Awareness with the wizard

Guides on using the wizard to configure user identification methods.

Configuring Local Users and User Groups

To add a new local user

Steps to add a new local user with remote access permissions.

To add a new local users group with remote access permissions

Adds new local user groups and configures their remote access permissions.

Managing Authentication Servers

To add a RADIUS server

Steps to add primary/secondary RADIUS servers with IP, port, and shared secret.

To add an Active Directory domain

Steps to add an Active Directory domain, including domain name and controller IP address.

Managing Applications & URLs

Managing System Services

Managing Network Objects

Logs and Monitoring

Configuring External Log Servers

SNMP

Advanced Configuration

Upgrade Using a USB Drive

Explains how to upgrade the appliance with a USB drive without a console connection.

Upgrade Using Boot Loader

Details how to upgrade the appliance using U-boot (boot loader) via network connection.

Restoring Factory Defaults

Explains how to restore the appliance to its factory default settings via WebUI or back panel button.

RESTful API

REST API Commands

Lists and describes REST API commands: Login, Logout, Generate-Report, Run-Clish-Command.

Related product manuals