Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
204
Layer 2 and Layer 3 Firewalls
213455-L, October 2005
To configure Layer 3 bridging firewall, use the following procedure on NSF#1 and then on
NSF#2.
1.
Configure basic firewall configuration on Switched Firewall, NSF#1.
In the initial setup of the firewall, (see
Setting up the basic configuration on page 37
) specify
port 1 for the management network and the firewall IP address 172.16.2.143. Specify VLAN
tag ID 0 with the MIP address, 172.16.2.145.
Configure sync and management interfaces on the same port (eth0).
2.
Configure basic firewall configuration on Switched Firewall, NSF#2.
In the initial setup of the firewall, (see
Setting up the basic configuration on page 37
) specify
port 1 for the management network and the firewall IP address 172.16.2.144. Specify VLAN
tag ID 0 for the management traffic. Configure sync and management interfaces on port 1
(eth0).
3.
Configure IP addresses and other parameters on both the firewalls.
Specify the ports participating in the Layer 3 firewall and set the VLAN ID if the ports are used
by other interfaces.
eth0: 172.16.2.143 (VLAN tag: 0)
MIP : 172.16.2.145 (eth0:1)
eth0 : 172.16.2.144 (VLAN tag:0)
>> # /cfg/net/
bridge 1
Bridge 1#
addr1 172.16.5.5
(Set address 1 for bridge 1)
Bridge 1#
addr2 172.16.5.6
(Set address 2 for bridge 1)
Bridge 1#
mask 255.255.255.0
Bridge 1#
ports
Bridge 1 Ports#
add 3
(Port 3 participates in the bridge)
Bridge 1 Ports#
add 4
(Port 4 participates in the bridge)
Bridge 1 Ports#
..
Bridge 1#
vrrp/ip1 172.16.5.1
VrrpBridge 1# ../
ena
(Enable bridge 1)