WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide WatchGuard Firebox System 7.0 User Guide

watchguard.com
from watchguard.com More from this publisher
11.07.2015 Views

Chapter 3: Getting StartedCharacteristics of a routed configuration:• All interfaces of the Firebox must be on differentnetworks. The minimum setup involves the externaland trusted interfaces.• The trusted and optional interfaces must be onseparate networks and all machines behind the trustedand optional interfaces must be configured with an IPaddress from that network.The benefit of a routed configuration is that the networksare well defined and easier to manage, especially regardingVPNs.Drop-in configurationIn a drop-in configuration, the Firebox is put in place withthe same network address on all Firebox interfaces. Allthree Firebox interfaces must be configured. Because thisconfiguration mode distributes the network’s logical30 WatchGuard Firebox System

Selecting a Firewall Configuration Modeaddress space across the Firebox interfaces, you can “drop”the Firebox between the router and the LAN withoutreconfiguring any local machines. Public servers behindthe Firebox use public addresses, and traffic is routedthrough the Firebox with no network address translation.Characteristics of a drop-in configuration:• A single network that is not subdivided into smallernetworks or subnetted.• The Firebox performs proxy ARP, a technique in whichone host answers Address Resolution Protocol requestsfor machines behind that Firebox that cannot hear thebroadcasts. The trusted interface ARP address replacesthe router’s ARP address.• The Firebox can be placed in a network withoutchanging default gateways on the trusted hosts. This isbecause the Firebox answers for the router, eventhough the router cannot hear the trusted host’s ARPrequests.User Guide 31

Selecting a Firewall Configuration Modeaddress space across the <strong>Firebox</strong> interfaces, you can “drop”the <strong>Firebox</strong> between the router and the LAN withoutreconfiguring any local machines. Public servers behindthe <strong>Firebox</strong> use public addresses, and traffic is routedthrough the <strong>Firebox</strong> with no network address translation.Characteristics of a drop-in configuration:• A single network that is not subdivided into smallernetworks or subnetted.• The <strong>Firebox</strong> performs proxy ARP, a technique in whichone host answers Address Resolution Protocol requestsfor machines behind that <strong>Firebox</strong> that cannot hear thebroadcasts. The trusted interface ARP address replacesthe router’s ARP address.• The <strong>Firebox</strong> can be placed in a network withoutchanging default gateways on the trusted hosts. This isbecause the <strong>Firebox</strong> answers for the router, eventhough the router cannot hear the trusted host’s ARPrequests.<strong>User</strong> <strong>Guide</strong> 31

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!