12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

About Multiple WAN Support3 Under Host IP, select the Obtain an IP address automatically check box if you want DHCP toassign an IP address to the Firebox. If you want to manually assign an IP address and use DHCP justto give this assigned address to the Firebox, select the Use IP address check box and enter the IPaddress in the adjacent field.4 IP addresses assigned by a DHCP server have a one-day lease, which means the address is valid forone day. If you want to change the leasing time, select the Specify Leasing Time check box andselect the value in the fields below the check box.About Multiple WAN SupportFireware® appliance software gives you the option to configure multiple external interfaces (up to four),each on a different subnet. This allows you to connect the Firebox® to more than one Internet ServiceProvider (ISP). As soon as you configure a second external interface, multiple WAN support is automaticallyenabled with multi-WAN in round robin order set as the default. There are three options to controlwhich interface outgoing packets use.Note that:• If you have a policy configured with an individual external interface alias in its configuration, youmust change the configuration to use the alias “Any-External”.• If you use the multiple WAN feature, map your company’s Fully Qualified Domain Name to theexternal interface IP address of the lowest order. If you add a multi-WAN Firebox to yourManagement Server configuration, you must add the Firebox using its lowest-ordered externalinterface to identify it.• You cannot use 1-to-1 NAT in a multiple WAN configuration. If you have a public SMTP serverbehind your Firebox, you must set up a static NAT rule to allow access to your public SMTP e-mailserver. Then, you can set up multiple MX records, one for each external Firebox interface.• If you have a multiple WAN configuration, you cannot use the policy-based, dynamic NAT SetSource IP option. Use the Set Source IP option only when your Firebox uses a single externalinterface.• Multiple WAN support does not apply to branch office or Mobile <strong>User</strong> VPN traffic. Branch officeand Mobile <strong>User</strong> VPN traffic always uses the first external interface configured for the Firebox.RUVPN with PPTP operates correctly in a multiple WAN configuration.• The multiple WAN feature is not supported in drop-in mode.About multi-WAN in round robin orderIf you select “round robin” order, you can share the load of outgoing traffic among external interfaceslike this:• The first host, with IP address x.x.x.x, sends an HTTP request to the Internet. The packets in thissession are sent through the lowest number external interface.• The second host, with IP address y.y.y.y, sends an HTTP request to the Internet. The packets in thissession are sent through the external interface with the second higher number.• The third host, with IP address z.z.z.z, sends an HTTP request to the Internet. The packets in thissession are sent through the lowest number external interface (if there are only two externalinterfaces configured) or the third higher number external interface.• As each host initiates a connection, the Firebox cycles through external interfaces using thepattern explained above.102 <strong>WatchGuard</strong> System Manager

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!