13.07.2015 Views

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

WatchGuard Firebox System 4.6 User Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Setting up a routed network• All three <strong>Firebox</strong> interfaces are assigned the same IP address. This is true whetheror not you use the Optional interface.• The majority of a LAN resides on the Trusted interface.• You can have other networks in other address ranges behind the <strong>Firebox</strong> usingsecondary networks. List the IP address of secondary networks in theconfiguration file.Use the sample network configuration and the Network Configuration Worksheet(found in the Install <strong>Guide</strong>) to design your drop-in network. Then either run theQuickSetup wizard to create a new configuration file or manually modify an existingconfiguration file using Policy Manager. To set up a drop-in network, from PolicyManager:1 Select Network => Configuration. Click the Drop-In Configuration tab.2 Enable the Automatic checkbox if you want the <strong>Firebox</strong> to use proxy ARP for allhosts. Disable the checkbox if you want the <strong>Firebox</strong> to use proxy ARP only onbehalf of all hists on the network you specify with the Default Network dropdownmenu.When automatic mode is enabled, the Hosts list is useful to lock a host to the specified interface.To add specific hosts that the <strong>Firebox</strong> should use proxy ARP for, enter the IP address and theinterface they reside on in the Hosts section of the Drop-In Configuration tab.3 Click Add to add a new host. To remove a host, select it and click Remove.4 When you are done setting up your network, click OK.Setting up a routed networkUse a routed network configuration when the <strong>Firebox</strong> is put in place with separatelogical networks on its interfaces. This configuration assigns separate networkaddresses to at least two of the three <strong>Firebox</strong> interfaces.If you have two separate network addresses and you want to use the routedconfiguration, use only the External and Trusted interfaces (not the Optionalinterface). Each interface must be on a separate network in routed configurationmode.If you have three or more network addresses, use the routed network configurationand map a network to each interface. Add more networks as secondary networks toone of the interfaces. You can relate different networks to different interfaces. Thosenetworks then come under the protection and access rules set up for that interface.The <strong>Firebox</strong> forwards packets to the various interfaces depending on how you defineand configure services in Policy Manager.Use the sample network configuration and the Network Configuration Worksheet(found in the Install <strong>Guide</strong>) to design your routed network. Then either run theQuickSetup wizard to create a new configuration file or manually modify an existingconfiguration file.<strong>User</strong> <strong>Guide</strong> 37

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!