Appendix B Triangle Route - Nortel Contivity 221 User Manual

Vpn switch
Hide thumbs Also See for Contivity 221:
Table of Contents

Advertisement

Appendix B
Triangle Route
The Ideal Setup
When the firewall is on, your Contivity 221 acts as a secure gateway between your LAN and the
Internet. In an ideal network topology, all incoming and outgoing network traffic passes through
the Contivity 221 to protect your LAN against attacks.
Diagram B-1 Ideal Setup
The "Triangle Route" Problem
A traffic route is a path for sending or receiving data packets between two Ethernet devices. Some
companies have more than one alternate route to one or more ISPs. If the LAN and ISP(s) are in
the same subnet, the "triangle route" problem may occur. The steps below describe the "triangle
route" problem.
Step 1.
Step 2.
Step 3.
As a result, the Contivity 221 resets the connection, as the connection has not been
acknowledged.
A computer on the LAN initiates a connection by sending out a SYN packet to
a receiving server on the WAN.
The Contivity 221 reroutes the SYN packet through Gateway B on the LAN to
the WAN.
The reply from the WAN goes directly to the computer on the LAN without
going through the Contivity 221.
Contivity 221 VPN Switch User's Guide
B-1

Advertisement

Table of Contents
loading

Table of Contents