D-Link NetDefend DFL-210 User Manual page 92

Network security firewall ver. 1.05
Hide thumbs Also See for NetDefend DFL-210:
Table of Contents

Advertisement

4.3.5. The Ordering parameter
This is a "drop-in" design, where there are no explicit routing subnets between the ISP gateways and the D-
Link Firewall.
In a provider-independent metropolitan area network, clients will likely have a single IP address, belonging to one
of the ISPs. In a single-organization scenario, publicly accessible servers will be configured with two separate IP
addresses: one from each ISP. However, this difference does not matter for the policy routing setup itself.
Note that, for a single organization, Internet connectivity through multiple ISPs is normally best done with the BGP
protocol, where you do not need to worry about different IP spans or policy routing. Unfortunately, this is not al-
ways possible, and this is where Policy Based Routing becomes a necessity.
We will set up the main routing table to use ISP A, and add a named routing table, "r2" that uses the default gate-
way of ISP B.
Interface
lan1
lan1
wan1
wan2
wan1
Contents of the named Policy-based Routing table r2:
Interface
wan2
The table r2 has its Ordering parameter set to Default, which means that it will only be consulted if the main rout-
ing table lookup matches the default route (0.0.0.0/0).
Contents of the Policy-based Routing Policy:
Source Inter-
face
lan1
wan2
To configure this example scenario:
Web Interface
1.
Add the routes found in the list of routes in the main routing table, as shown earlier.
2.
Create a routing table called "r2" and make sure the ordering is set to "Default".
3.
Add the route found in the list of routes in the routing table "r2", as shown earlier.
4.
Add two VR policies according to the list of policies shown earlier.
Routing > Routing Rules > Add > RoutingRule
Enter the information found in the list of policies displayed earlier.
Repeat the above to add the second rule.
Network
1.2.3.0/24
2.3.4.0/24
1.2.3.1/32
2.3.4.1/32
0.0.0.0/0
Network
0.0.0.0/0
Source
Destination
Range
Interface
1.2.3.0/24
wan2
0.0.0.0/0
lan1
Note
Rules in the above example are added for both inbound and outbound connections.
Gateway
1.2.3.1
Gateway
2.3.4.1
Destination
Service
Range
0.0.0.0/0
ALL
2.3.4.0/24
ALL
79
Chapter 4. Routing
ProxyARP
wan1
wan1
wan1
lan1
Forward
VR
Return VR ta-
table
ble
r2
r2
r2
r2

Advertisement

Table of Contents
loading

Table of Contents