Administrator's Guide - Kerio Software Archive

Administrator's Guide - Kerio Software Archive Administrator's Guide - Kerio Software Archive

download.kerio.com
from download.kerio.com More from this publisher
30.01.2015 Views

Chapter 6 Internet Connection The basic function of Kerio Control is connection of the local network to the Internet via one or more Internet connections (Internet links). Depending on number and types of Internet links, Kerio Control provides various options of Internet connection: A Single Internet Link — Persistent The most common connection of local networks to the Internet. In this case, only one Internet connection is available and it is used persistently (typically Ethernet, WiFi, ADSL or cable modems). It is also possible to use dial-like links which can be connected persistently, such as PPPoE connections or CDMA modems. A Single Internet Link — Dial On Demand This type of connection is fit for links which are charged by connection time — typically modems for analog or ISDN links. The link is down by default and Kerio Control dials it in response to a query demanding access from the local network to the Internet. If no data are transferred via the link for some time, Kerio Control hangs it up to reduce connection costs. Multiple Internet Links — Failover Where reliability (availability of the Internet connection) is an issue and two Internet links are available, the connection failover feature can help. If the primary link fails, Kerio Control switches to the secondary link automatically. Users may therefore notice just a very short disconnection of the Internet connection. When the connection on the primary link is recovered, Kerio Control automatically switches back to it. For most part of users, this operation takes so short to be even noticeable. Multiple Internet Links Traffic Load Balancing If throughput (connection speed) is an issue, Kerio Control can use multiple links concurrently and spread data transferred between the LAN and the Internet among these links. In standard conditions and settings, this also works as connection failover — if any of the links fails, transferred data are spread among the other (working) links. In all cases, Kerio Control works in the mode of shared Internet connection. Sharing uses the NAT (IP address translation) technology, hiding the entire local network behind a public IP address of the firewall (or multiple addresses — depending on the type of Internet connection applied). Kerio Control can also be used as a neutral router (router without NAT). However, this mode is not the best connection of the LAN to the Internet — it requires expert configuration and advanced security. This involves selection of the Internet connection type in the Configuration → Interfaces section of the Kerio Control configuration, setting corresponding interfaces for connection to the Internet and definition of corresponding traffic rules (see chapter 7.3). 60

6.1 Persistent connection with a single link Hint: All necessary settings can be done semi-automatically with use of Traffic Policy Wizard — see chapter 7.1. Following chapters provide with guidelines for setting of individual Internet connection types as well as with description on configuration of the corresponding interface and traffic rules in the wizard. The information available there can be used for customization of settings (e.g. for setting of a new local subnetwork or for change of Internet connection). 6.1 Persistent connection with a single link Requirements The Kerio Control hosting computer must be connected to the Internet by a leased line (typically Ethernet or WiFi card). Parameters of this interface will be set with use of information supplied by the ISP provider or they can be configured automatically with the DHCP protocol. It is also possible to use a dial-like link which can be connected persistently, such as PPPoE connections or CDMA modems. Kerio Control will keep this type of link connected persistently (in case of connection failure, the connection is automatically recovered immediately). This connection type also requires one or more network cards for connection of individual segments of the LAN. Default gateway must NOT be set on any of these cards! If possible, it is also recommended functionality of the Internet connection before installing Kerio Control. Configuration with the wizard On the second page of the Traffic Policy Wizard (see chapter 7.1), select A Single Internet Link — Persistent. On the third page of the wizard, select a network interface (Internet link). As a preselection, the interface where Kerio Control detected the default gateway is used. Therefore, in most cases the appropriate adapter is already set within this step. If you select a link which is defined as a dial-up (see above), valid username and password are required. If this information is saved in the operating system, Kerio Control can enter it automatically. In the Software Appliance / VMware Virtual Appliance edition, the wizard allows: 61

Chapter 6<br />

Internet Connection<br />

The basic function of <strong>Kerio</strong> Control is connection of the local network to the Internet via one or<br />

more Internet connections (Internet links). Depending on number and types of Internet links,<br />

<strong>Kerio</strong> Control provides various options of Internet connection:<br />

A Single Internet Link — Persistent<br />

The most common connection of local networks to the Internet. In this case, only one<br />

Internet connection is available and it is used persistently (typically Ethernet, WiFi, ADSL<br />

or cable modems). It is also possible to use dial-like links which can be connected<br />

persistently, such as PPPoE connections or CDMA modems.<br />

A Single Internet Link — Dial On Demand<br />

This type of connection is fit for links which are charged by connection time — typically<br />

modems for analog or ISDN links. The link is down by default and <strong>Kerio</strong> Control dials<br />

it in response to a query demanding access from the local network to the Internet. If<br />

no data are transferred via the link for some time, <strong>Kerio</strong> Control hangs it up to reduce<br />

connection costs.<br />

Multiple Internet Links — Failover<br />

Where reliability (availability of the Internet connection) is an issue and two Internet<br />

links are available, the connection failover feature can help. If the primary link fails,<br />

<strong>Kerio</strong> Control switches to the secondary link automatically. Users may therefore notice<br />

just a very short disconnection of the Internet connection. When the connection on the<br />

primary link is recovered, <strong>Kerio</strong> Control automatically switches back to it. For most part<br />

of users, this operation takes so short to be even noticeable.<br />

Multiple Internet Links Traffic Load Balancing<br />

If throughput (connection speed) is an issue, <strong>Kerio</strong> Control can use multiple links<br />

concurrently and spread data transferred between the LAN and the Internet among these<br />

links. In standard conditions and settings, this also works as connection failover — if any<br />

of the links fails, transferred data are spread among the other (working) links.<br />

In all cases, <strong>Kerio</strong> Control works in the mode of shared Internet connection. Sharing uses the<br />

NAT (IP address translation) technology, hiding the entire local network behind a public IP<br />

address of the firewall (or multiple addresses — depending on the type of Internet connection<br />

applied). <strong>Kerio</strong> Control can also be used as a neutral router (router without NAT). However, this<br />

mode is not the best connection of the LAN to the Internet — it requires expert configuration<br />

and advanced security.<br />

This involves selection of the Internet connection type in the Configuration → Interfaces<br />

section of the <strong>Kerio</strong> Control configuration, setting corresponding interfaces for connection<br />

to the Internet and definition of corresponding traffic rules (see chapter 7.3).<br />

60

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!