11.07.2015 Views

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Selecting a Firewall Configuration ModeCriterion 1Criterion 2Criterion 3Routed ConfigurationAll interfaces of the<strong>Firebox</strong> are on differentnetworks. Minimumconfigured are external andtrusted.Trusted and optionalinterfaces must be onseparate networks andmust use IP addressesdrawn from thosenetworks. Both interfacesmust be configured with anIP address on the samenetwork, respectively.Use static NAT to map anypublic addresses to privateaddresses behind thetrusted or optionalinterfaces.Drop-in ConfigurationAll interfaces of the<strong>Firebox</strong> are on the samenetwork and have the sameIP address (Proxy ARP).Machines on the trusted oroptional interfaces can beconfigured with a public IPaddress.Because machines that arepublicly accessible havepublic IP addresses, nostatic NAT is necessary.Adding secondary networks to yourconfigurationWhether you have chosen routed or drop-in, your configurationmay require that you add secondary networks toany of the three <strong>Firebox</strong> interfaces. A secondary network isa separate network connected to a <strong>Firebox</strong> interface by aswitch or hub.<strong>User</strong> <strong>Guide</strong> 33

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!