Tavve zoneranger User Manual page 27

Table of Contents

Advertisement

For example, consider the network in the following figure:
Figure 8-2. GVI Example
In the example, a Ranger Gateway is being used to manage two firewall-partitioned networks. Two
ZoneRangers have been deployed into each of these networks. In order to intercept management traffic
destined for these networks, two GVI subnet routes have been configured:
10.1.1.0/24
10.1.2.0/24
When the GVI service is enabled, the GVI route manager will automatically create static routes
indicating that traffic destined for these subnets should be routed to the GVI interface's remote address
(192.168.48.2). Given that the IP addresses of each of the ZoneRangers lie within these subnets, the GVI
route manager will automatically create host routes for each of the joined ZoneRangers indicating that
traffic destined for the ZoneRanger addresses should be routed via the original default gateway that was
configured for the Ranger Gateway server (64.1.2.1). The figure also shows the original default routing
rule (0.0.0.0/0 → 64.1.2.1), and a simple Proxy Map configuration indicating which ZoneRangers
should be used to proxy traffic for which device addresses.
If the GVI service is enabled, and a request to join to a given ZoneRanger is received by the Ranger
Gateway, the GVI route manager will automatically create a host route for that IP address, where
necessary to ensure that traffic destined for the ZoneRanger will bypass the virtual interface. Host routes
for joined ZoneRangers will automatically be removed from the system routing table if the ZoneRanger
is unjoined, any overlapping virtual interface routes are removed, or the GVI service is disabled.
The GVI service can be controlled and configured using the Ranger Gateway Viewer or the gvi Ranger
Gateway command.
On Windows servers, once the GVI is enabled, run the Windows command ncpa.cpl to display the
current list of network interfaces. Using the Advanced > Advanced Settings... menu item, verify that
the GVI virtual interface is last in the access order for network services.
ZoneRanger 5.5 User's Guide
27

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents