Nortel BSR252 Configuration - Basics page 175

Business secure router
Hide thumbs Also See for BSR252:
Table of Contents

Advertisement

If you list a general rule before a specific rule, traffic that you want to be
controlled by the specific rule can get the general rule applied to it instead. Any
traffic that does not match the first firewall rule matches the default rule and the
Business Secure Router forwards the traffic.
Note: If an alternate gateway on the LAN has an IP address in the same
subnet as the Business Secure Router LAN IP address, return traffic does
not go through the Business Secure Router. This is called an
asymmetrical or triangle route, and causes the Business Secure Router to
reset the connection, as the connection has not been acknowledged.
Note: Allowing asymmetrical routes can let traffic from the WAN go
directly to the LAN without passing through the Business Secure Router.
A better solution is to use IP alias to put the Business Secure Router and
the backup gateway on separate subnets. See the Appendix B "Triangle
Route" of Nortel Business Secure Router 252 Configuration —
Advanced (NN47923-501) for more about triangle route topology.
Nortel Business Secure Router 252 Configuration — Basics
Chapter 11 Firewall screens 175

Advertisement

Table of Contents
loading

Table of Contents