Hybrid Mode; Link Aggregation (Lacp) - Sn510, Sn710, Sn910, Sn2000, Sn3000, Sn6000 And Ng Models; Conclusion; Presentation Of The Configuration Screen - Stormshield SN series Configuration Manual

Hide thumbs Also See for SN series:
Table of Contents

Advertisement

compatibility with IPX (Novell network), Netbios in Netbeui, Appletalk or IPv6.
l
no address translation, therefore time-saving as far as firewall packet treatment is concerned.
l
This mode is therefore recommended between the external zone and the DMZ. It allows keeping a
public address range on the firewall's external zone and on the DMZ's public servers.

Hybrid mode

In hybrid mode: some interfaces have the same IP address and others have a distinct address.
The hybrid mode uses a combination of both modes mentioned earlier. This mode may only be
used with Stormshield Network products having more than two network interfaces. You may
define several interfaces in transparent mode
Example
Internal zone and DMZ (or external zone and DMZ) and certain interfaces in a different address
range. As such, you have greater flexibility when integrating the product.
Link aggregation (LACP) – SN510, SN710, SN910, SN2000, SN3000, SN6000 and NG
models
The LACP (IEEE 802.3ad - Link Aggregation Control Protocol) or Aggregation of links allows
improving the appliance's bandwidth while maintaining a high level of availability (link
redundancy).
Several physical ports on an appliance can be grouped together to be considered a single logical
interface. Therefore, by aggregating x links, it will be possible to set up a link of x times 1 Gbps or
10 Gbps between two appliances.
This feature is only available on SN510, SN710, SN910, SN2000, SN3000, SN6000, NG1000 and
NG5000 models.
Ensure that the remote appliances are using LACP.

Conclusion

The choice of a mode is made only where network interface configuration is concerned. The
configuration of the firewall is then the same for all modes.
Security-wise, all operating modes are equal. The same things are filtered and attack detection
is identical.

Presentation of the configuration screen

The interface configuration window consists of 3 sections:
The directory of interfaces: the appliance's interfaces are presented sorted in the following
l
order: Bridge, Interface, VLAN, Modem according to the selected view. Clicking on an interface
allows viewing its configuration. It is also possible to use the search engine to look for a
specific interface. (Example: by typing "br", all bridges will be displayed).
The configuration panel (central panel) : by clicking on an interface in the directory, its
l
configuration will appear in this panel.
The toolbar: this bar allows:
l
Page 181/448
NOTE
SNS - USER CONFIGURATION MANUAL V.3
sns-en-user_configuration_manual-v3 - Copyright © Stormshield 2016
INTERFACES

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents