Ethernet Interfaces In D-Link Firewalls - D-Link DFL-1600 User Manual

Network security firewall
Hide thumbs Also See for DFL-1600:
Table of Contents

Advertisement

54
Chapter 9. Interfaces
firewall will be enumerated and configured during the local console setup
process. Each physical Ethernet adapter will become an Ethernet interface
and a name will be given in the firewall configuration. Administrators can
customize the descriptive name and change the IP addresses of an interface
after the primary installation.
9.1.2

Ethernet Interfaces in D-Link Firewalls

Configuration of an Ethernet interface mainly includes specifying the name
and the addresses. An IP address is bound to every interface that may be
used to ping the firewall, remotely control it, and be set by the firewall as
source address for dynamically translated connections. An additional IP
address can be published on an interface using ARP to simulate the effect
of an interface having more than one IP (See
9.6
ARP). Moreover,
administrators can apply dynamic address assignment to a network by
enabling DHCP client on the corresponding interface (See
9.3
DHCP).
As advanced features, High Availability(HA) & Transparency can be
implemented on the basis of firewall interfaces.
The HA enabled interfaces share one common IP address and each has a
private IP address to uniquely identify one cluster node. The private IP is
derived from the HA IP4 Address Pair configured in the Address
Book object (See
XIII High Availability
for more information about HA
cluster scenarios).
When setting up an interface to use transparent mode, the firewall will act
as a layer 2 switch and screen the traffic going through that interface
without modifying the source or destination address information. Both
sides of the communication will be unaware of the presence of the firewall.
For transparent mode configuration on interfaces, please refer to
27
Transparency.
Note
In the firewall, there are two logical interfaces named as "core" and
"any" respectively. "core" locates at the heart of the firewall, all traffic
from the physical interfaces are forwarded to "core" to be controlled by
security policies. "any" represents all possible interfaces including "core".
D-Link Firewalls User's Guide

Advertisement

Table of Contents
loading

Table of Contents