D-Link DFL-1660 User Manual page 170

Network security firewall
Hide thumbs Also See for DFL-1660:
Table of Contents

Advertisement

4.2.1. The Principles of Routing
Route #
2
3
4
The above routing table provides the following information:
Route #1
All packets going to hosts on the 192.168.0.0/24 network should be sent out on the lan interface.
As no gateway is specified for the route entry, the host is assumed to be located on the network
segment directly reachable from the lan interface.
Route #2
All packets going to hosts on the 10.4.0.0/16 network are to be sent out on the dmz interface.
Also for this route, no gateway is specified.
Route #3
All packets going to hosts on the 195.66.77.0/24 network will be sent out on the wan interface.
No gateway is required to reach the hosts.
Route #4
All packets going to any host (the all-nets network will match all hosts) will be sent out on the
wan interface and to the gateway with IP address 195.66.77.4. That gateway will then consult its
routing table to find out where to send the packets next.
A route with the destination all-nets is often referred to as the Default Route as it will match all
packets for which no specific route has been configured. This route usually specifies the
interface which is connected to the public internet.
The Narrowest Routing Table Match is Selected
When a routing table is evaluated, the ordering of the routes is not important. Instead, all routes in
the relevant routing table are evaluated and the most specific route is used. In other words, if two
routes have destination networks that overlap, the narrower network definition will be taken before
the wider one. This behavior is in contrast to IP rules where the first matching rule is used.
In the above example, a packet with a destination IP address of 192.168.0.4 will theoretically match
both the first route and the last one. However, the first route entry is a narrower, more specific
match so the evaluation will end there and the packet will be routed according to that entry.
Although routing table ordering is not important, it is still recommended for readability to try and
place narrower routes first and the default all-nets route last.
The Local IP Address Parameter
The correct usage of the Local IP Address parameter can be difficult to understand so additional
explanation can be helpful.
Normally, a physical interface such as lan is connected to a single network and the interface and
network are on the same network. We can say that the network is bound to a physical interface and
clients on the connected network can automatically find the NetDefend Firewall through ARP
queries. ARP works because the clients and the NetDefendOS interface are part of the same
network.
Interface
Destination
dmz
10.4.0.0/16
wan
195.66.77.0/24
wan
170
Chapter 4. Routing
Gateway
all-nets
195.66.77.4

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Dfl-2560Dfl-2560gDfl-260eDfl-860e

Table of Contents