. . . . .
S E C U R I T Y Z O N E S A N D I N T E R F A C E S
Configuring Interface Modes
Version 3R2
Security Appliance User Guide
3-15
Telnet disabled, DHCP disabled
zone global
G U I E X A M P L E : G E T T I N G I N T E R F A C E E T H 0
1
Network > Interface > Edit (for ETH0)
Displays interface for ETH0
CONFIGURING TRANSPARENT MODE
This section describes the Transparent Mode feature. It includes the
following topics:
•
Transparent Mode Overview
•
Transparent Mode Simple Deployment
•
Transparent Mode Simple ACL Functions
T R A N S P A R E N T M O D E O V E R V I E W
When the freeGuard Blaze 2100 is configured to run in Transparent
mode the device is configured with the same network on both interfaces.
In this mode the freeGuard Blaze 2100 functions like a layer 2 switch or
bridge. As packets traverse through the firewall they will do so without
having their src/dest IP/MAC address information changed in the header,
allowing the freeGuard Blaze 2100 to be deployed in complex networks
un-obtrusively.
In Transparent mode the freeGuard Blaze 2100 can be deployed deep
within a core network as it will pass all traffic without additional
configuration. All routing protocols, and broadcast protocols can be
passed seamlessly through the freeGuard Blaze 2100. While in this mode
the freeGuard Blaze 2100 can be further configured to bypass various
network security functions that in some cases are not desired by the
network/security administrator.
In addition to passing various protocols without interception, the
freeGuard Blaze 2100 Transparent mode supports VLAN (802.1q)
recognition and filtering. If desired, the freeGuard Blaze 2100 can be
deployed into an existing VLAN network, and be configured to recognize
the various 802.1q packets and apply traffic policies using its zone-based
filter. This function is called Transparent-VLAN filtering and is described
in
Transparent Mode VLAN Filtering on page 3 - 18
.