12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Installing <strong>WatchGuard</strong> System ManagerOptional interface(s)Usually connects to the DMZ or the mixed trust area of your network. The number of optionalinterfaces on your Firebox changes with the model you have purchased. Use optional interfacesto create zones in the network with different levels of access.Network IP Address With the FireboxDefault GatewayExternal NetworkTrusted NetworkOptional NetworkSecondary Network(if applicable)_____._____._____.__________._____._____._____ / _________._____._____._____ / _________._____._____._____ / _________._____._____._____ / ____Selecting a firewall configuration modeYou must decide how to install the Firebox into your network before you install <strong>WatchGuard</strong> SystemManager. How you install the Firebox controls the interface configuration. To install the Firebox intoyour network, select the configuration mode—routed or drop-in—that matches the needs of your currentnetwork.Many networks operate best with a routed configuration, but we recommend the drop-in mode if:• You have already assigned a large number of static IP addresses• You cannot configure the computers on your trusted and optional networks that have public IPaddresses with private IP addressesThis table and the descriptions below the table show three conditions that can help you to select a firewallconfiguration mode.Routed ConfigurationAll interfaces of the Firebox are on differentnetworks.Trusted and optional interfaces must be ondifferent networks. Each interface has an IPaddress on its network.Use static NAT (network address translation)to map public addresses to private addressesbehind the trusted or optional interfaces.Drop-in ConfigurationAll interfaces of the Fireboxare on the same network andhave the same IP address.The computers on the trustedor optional interfaces canhave a public IP address.The machines that have publicaccess have public IPaddresses. Thus, no static NATis necessary.Routed configurationUse the routed configuration when you have a small number of public IP addresses or when your Fireboxgets its external IP address with PPPoE (point-to-point protocol over Ethernet) or DHCP (dynamichost configuration protocol).<strong>User</strong> <strong>Guide</strong> 11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!