D-Link DFL-1600 User Manual page 308

Network security firewall
Hide thumbs Also See for DFL-1600:
Table of Contents

Advertisement

288
Chapter 27. Transparent Mode
Example:
Transparent Mode Scenario 2
Figure 27.2: Transparent Mode Scenario 2.
Scenario 2 shows how a firewall in Transparent Mode can be used to
separate server resources from the internal network by attaching them to a
separate firewall interface without the need of different address ranges.
Servers containing resources that is accessible from the outside could be a
security risk if they are placed directly on the internal network. Because of
this, such servers are often connected to a separate interface on the firewall,
like DMZ.
In this scenario all hosts connected to LAN and DMZ shares the
10.0.0.0/24 address space. As this is configured using Transparent Mode
any IP address can be used for the servers, and there is no need for the
hosts on the internal network to know if a resource is on the same network
or placed on DMZ. This makes the firewall transparent in the
communication between DMZ and LAN even though the traffic can be
restricted using the firewall's
IP
ruleset.
Here we allow the hosts on the internal network to communicate with an
HTTP server on DMZ. Furthermore, we allow the HTTP server on DMZ to
be reached from the internet. Additional rules could be added to allow
other traffic.
D-Link Firewalls User's Guide

Advertisement

Table of Contents
loading

Table of Contents