Transparent bridge mode
In transparent bridge mode, the communicating devices are unaware of the appliance — the
appliance’s operation is transparent to the devices.
Figure 1: Transparent communication
In
Figure 1: Transparent communication
, the external mail server (A) sends email messages
to the internal mail server (C). The external mail server is unaware that the email message is
intercepted and scanned by the appliance (B).
The external mail server seems to communicate directly with the internal mail server — the
path is shown as a dotted line. In reality, traffic might pass through several network devices
and be intercepted and scanned by the appliance before reaching the internal mail server.
What the appliance does
In transparent bridge mode, the appliance connects to your network using the LAN1 and LAN2
ports. The appliance scans the traffic it receives, and acts as a bridge connecting two separate
physical networks, but treats them as a single logical network.
Configuration
Transparent bridge mode requires less configuration than transparent router and explicit proxy
modes. You do not need to reconfigure all your clients, default gateway, MX records, Firewall
NAT or mail servers to send traffic to the appliance. Because the appliance is not a router in
this mode, you do not need to update a routing table.
Where to place the appliance
For security reasons, you must use the appliance inside your organization, behind a firewall.
Figure 2: Single logical network
TIP:
In transparent bridge mode, position the appliance between the firewall and your router,
as shown in
Figure 2: Single logical network
.
In this mode, you physically connect two network segments to the appliance, and the appliance
treats them as one logical network. Because the devices — firewall, appliance, and router —
are on the same logical network, they must all have compatible IP addresses on the same
subnet.
Devices on one side of the bridge (such as a router) that communicate with devices on the
other side of the bridge (such as a firewall) are unaware of the bridge. They are unaware that
Pre-installation
Considerations about Network Modes
11
McAfee Email and Web Security Appliance 5.1 Installation Guide