11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Selecting a Firewall Configuration ModeTrusted interfaceConnects to the private LAN or internal networkthat you want protected.Optional interfaceConnects to the DMZ (Demilitarized Zone) ormixed trust area of your network. Computers onthe optional interface contain content you do notmind sharing with the rest of the world. Commonapplications housed on this interface are Web,email, and FTP servers.To decide how to incorporate the <strong>Firebox</strong> into your network,select the configuration mode that most closelyreflects your existing network. You must select one of twopossible modes: routed or drop-in configuration.Routed configurationIn a routed configuration, the <strong>Firebox</strong> is put in place withseparate logical networks and separate network addresseson its interfaces. Routed configuration is used primarilywhen the number of public IP addresses is limited or whenyou have dynamic IP addressing on the external interface.For more information on dynamic IP addressing on theexternal interface, see “Dynamic IP support on the externalinterface” on page 35. Public servers behind the <strong>Firebox</strong>use private addresses, and traffic is routed using networkaddress translation (NAT).<strong>User</strong> <strong>Guide</strong> 29

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!