D-Link NetDefend DFL-210 User Manual page 170

Network security firewall
Hide thumbs Also See for NetDefend DFL-210:
Table of Contents

Advertisement

4.7.1. Overview
Chapter 4. Routing
For example, if the interfaces if1 to if6 appear in a switch routes in routing table A, the resulting
interconnections will be as illustrated below.
Connecting together switch routes in this way only applies, however, if all interfaces are associated
with the same routing table. The situation where they are not, is described next.
Creating Separate Transparent Mode Networks
If we now have two routing tables A and B so that interfaces if1, if2 and if3 appear in a switch route
in table A and interfaces if4, if5, if6 appear in a switch route in table B, the resulting interconnections
will be as illustrated below.
The diagram above illustrates how switch route interconnections for one routing table are
completely separate from the switch route interconnections for another routing table. By using
different routing tables in this way we can create two separate transparent mode networks.
The routing table used for an interface is decided by the PBR Membership parameter for each
interface (PBR is short for Policy Based Routing which is the NetDefendOS term used for multiple
routing tables). To implement separate Transparent Mode networks, interfaces must have their PBR
Membership reset.
By default, all interfaces have PBR membership set to be all routing tables. By default, one main
routing table always exists and once an additional routing table has been defined, the PBR
membership for any interface can then be set to be that new table.
Transparent Mode with VLANs
If transparent mode is being set up for all hosts and users on a single VLAN then the technique
described above of using multiple routing tables also applies. A dedicated routing table should be
defined for a single VLAN and one switch route should then be defined in that routing table which
refers to an interface group. The interface group needs to contain all the interfaces involved in the
VLAN.
Enabling Transparent Mode Directly on Interfaces
The recommended way to enable Transparent Mode is to add switch routes, as described above. An
170

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents