Bridging; Adding A Bridged Interface - McAfee SG310 Administration Manual

Utm firewall
Table of Contents

Advertisement

Network Setup menu options

Bridging

[Optional] To enable RTS, select the Enable RTS checkbox. Default: Disabled.
7
[Conditional; complete if RTS is enabled] Enter a minimum packet size in the RTS Threshold field.
8
Collisions are less likely for smaller packets, and so the overhead of using RTS for these might not be
worthwhile. The field attributes are as follows:
• Range 1-2346
• Default: 2346
[Optional] To enable, select the Enable Fragmentation checkbox. Default: Disabled.
9
Enter a fragment size in the Fragmentation Length field. Smaller fragments decrease the amount
10
retransmitted when there is an error; however, it increases the total processing overhead for each packet.
• Range 256-2345
• Default: 2345
Specify the interval between beacon frames in the Beacon Interval (ms) field.
11
• Range 20-999
• Default: 100
Specify how often a DTIM interval is included in the beacon frame in the DTIM Interval (beacons) field.
12
• Range 1-255
• Default: 1
Click Update.
13
Bridging
The appliance can be configured to bridge between network interfaces. When two or more network
interfaces are bridged, the appliance learns and keeps track of which hosts are reside on either side of the
bridge, and automatically directs network traffic appropriately.
One advantage of bridging network interfaces is that hosts on either side of the bridge can communicate
with hosts on the other side without having to specify a route to the other network via the appliance.
Another advantage is that network traffic not usually routed by an unbridged interface, such as broadcast
packets, multicast packets, and any non-IPv4 protocols such as IPv6, IPX, or Appletalk pass over the bridge
to their destination host.
Caution:
You must trust all devices that are directly connected to bridged interfaces. Since the firewall does not
know which IP addresses for the bridged network belong on which interface, this means it is easy for a directly
connected device to spoof an IP address. You can manually add Packet Filter rules to prevent spoofing.
Furthermore, non-IP protocols are not restricted by the firewall. You should not bridge between interfaces
with different firewall classes if you are using non-IP protocols. Bridging only supports Ethernet and GRE
network interfaces. Since bridging can only be configured as a Direct Connection, you cannot bridge a
PPPoE connection. If you want to bridge a wireless interface to a LAN connection, see
LAN
connections.

Adding a bridged interface

Use this procedure to add a bridged network interface. When network interfaces are bridged, they all share
a common configuration for the network connection. This means that a single IP address is used on all of
the network interfaces. Bridging network interfaces involves creating and then associating existing network
interfaces with a Bridge interface. Once this bridge interface has been added, it appears on the Network
Setup page under the Connections tab, along with the UTM Firewall appliance's other network interfaces.
Prerequisites:
• If high availability is configured for a connection, it must be modified or disabled before bridging.
94
McAfee UTM Firewall 4.0.4 Administration Guide
Bridging wireless and

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg560Sg560uSg565Sg580

Table of Contents