11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 3: Getting Started• All trusted computers must have their ARP cachesflushed.• The majority of a LAN resides on the trusted interfaceby creating a secondary network for the LAN.The benefit of a drop-in configuration is that you don’thave to reconfigure machines already on a public networkwith private IP addresses. The drawback is that it is generallyharder to manage and is more prone to network problems.Choosing a <strong>Firebox</strong> configurationThe decision between routed and drop-in mode is based onyour current network. Many networks are best served byrouted mode. However, drop-in mode is recommended ifyou have a large number of public IP addresses, you have astatic external IP address, or you are not willing or able toreconfigure machines on your LAN. The following tablesummarizes the criteria for choosing a <strong>Firebox</strong> configuration.(For illustrative purposes, it is assumed that the dropinIP address is a public address.)32 <strong>WatchGuard</strong> <strong>Firebox</strong> <strong>System</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!