WatchGuard Firebox System 7.0 User Guide

WatchGuard Firebox System 7.0 User Guide WatchGuard Firebox System 7.0 User Guide

watchguard.com
from watchguard.com More from this publisher
11.07.2015 Views

Chapter 3: Getting StartedWhen you add a secondary network, you map an IPaddress from the secondary network to the IP address ofthe Firebox interface. This is known as creating (or adding)an IP alias to the network interface. This IP alias becomesthe default gateway for all the machines on the secondarynetwork. The presence of a secondary network also tellsthe Firebox that another network resides on the Fireboxinterface wire.You add secondary networks in the following two ways:• The QuickSetup Wizard, which is part of theinstallation process, asks you to select the checkbox ifyou have “an additional private network behind theFirebox” when you are entering the IP addresses forthe Firebox interfaces. The additional private networkyou specify becomes the secondary network on thetrusted interface. For more information on theQuickSetup Wizard, see “Running the QuickSetupWizard” on page 40.34 WatchGuard Firebox System

Selecting a Firewall Configuration Mode• After you have finished with the installation, you canadd secondary networks to any interface using PolicyManager, as described in “Adding SecondaryNetworks” on page 64.Dynamic IP support on the external interfaceIf you are supporting dynamic IP addressing, you mustchoose routed configuration.If you choose the Dynamic Host Configuration Protocol(DHCP) option, the Firebox will request its IP address,gateway, and netmask from a DHCP server managed byyour Internet Service Provider (ISP). This server can alsoprovide WINS and DNS server information for your Firebox.If it does not, you must add it manually to your configuration,as described in “Entering WINS and DNSServer Addresses” on page 65. You can also change theWINS and DNS values provided by your ISP, if necessary.Point-to-Point Protocol over Ethernet (PPPoE) is also supported.As with DHCP, the Firebox initiates a PPPoE protocolconnection to your ISP’s PPPoE server, whichautomatically configures your IP address, gateway, andnetmask. However, PPPoE does not propagate DNS andWINS server information as DHCP does.If you are using PPPoE on the external interface, you willneed the PPP user name and password when you set upyour network. Both username and password each have a256-byte capacity.When the Firebox is configured such that it obtains its IPaddresses dynamically, the following functionality (whichrequires a static IP address) is not supported unless you arecertain that the dynamic IP settings sent by your ISP willnot change:• High Availability (not supported on Firebox 500)• Drop-in mode• 1-to-1 NATUser Guide 35

Selecting a Firewall Configuration Mode• After you have finished with the installation, you canadd secondary networks to any interface using PolicyManager, as described in “Adding SecondaryNetworks” on page 64.Dynamic IP support on the external interfaceIf you are supporting dynamic IP addressing, you mustchoose routed configuration.If you choose the Dynamic Host Configuration Protocol(DHCP) option, the <strong>Firebox</strong> will request its IP address,gateway, and netmask from a DHCP server managed byyour Internet Service Provider (ISP). This server can alsoprovide WINS and DNS server information for your <strong>Firebox</strong>.If it does not, you must add it manually to your configuration,as described in “Entering WINS and DNSServer Addresses” on page 65. You can also change theWINS and DNS values provided by your ISP, if necessary.Point-to-Point Protocol over Ethernet (PPPoE) is also supported.As with DHCP, the <strong>Firebox</strong> initiates a PPPoE protocolconnection to your ISP’s PPPoE server, whichautomatically configures your IP address, gateway, andnetmask. However, PPPoE does not propagate DNS andWINS server information as DHCP does.If you are using PPPoE on the external interface, you willneed the PPP user name and password when you set upyour network. Both username and password each have a256-byte capacity.When the <strong>Firebox</strong> is configured such that it obtains its IPaddresses dynamically, the following functionality (whichrequires a static IP address) is not supported unless you arecertain that the dynamic IP settings sent by your ISP willnot change:• High Availability (not supported on <strong>Firebox</strong> 500)• Drop-in mode• 1-to-1 NAT<strong>User</strong> <strong>Guide</strong> 35

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!