beautypg.com

7 transparent firewalls, 8 configuring device mode (router) – ZyXEL Communications ZyXEL ZyWALL 2WG User Manual

Page 458

background image

Chapter 26 Maintenance

ZyWALL 2WG User’s Guide

458

For example, if a bridge receives a frame via port 1 from host A (MAC address
00a0c5123478), the bridge associates host A with port 1. When the bridge receives another
frame on one of its ports with destination address 00a0c5123478, it forwards the frame
directly through port 1 after checking the internal table.
The bridge takes one of these actions after it checks the destination address of an incoming
frame with its internal table:

• If the table contains an association between the destination address and any of the bridge's

ports aside from the one on which the frame was received, the frame is forwarded out the
associated port.

• If no association is found, the frame is flooded to all ports except the inbound port.

Broadcasts and multicasts also are flooded in this way.

• If the associated port is the same as the incoming port, then the frame is dropped (filtered).

26.7 Transparent Firewalls

A transparent firewall (also known as a transparent, in-line, shadow, stealth or bridging
firewall) has the following advantages over “router firewalls”:

1 The use of a bridging firewall reduces configuration and deployment time because no

networking configuration changes to your existing network (hosts, neighboring routers
and the firewall itself) are needed. Just put it in-line with the network it is protecting. As
it only moves frames between ports (after inspecting them), it is completely transparent.

2 Performance is improved as there's less processing overhead.
3 As a transparent bridge does not modify the frames it forwards, it is effectively “stealth”

as it is invisible to attackers.

Bridging devices are most useful in complex environments that require a rapid or new firewall
deployment. A transparent, bridging firewall can also be good for companies with several
branch offices since the setups at these offices are often the same and it's likely that one design
can be used for many of the networks. A bridging firewall could be configured at HQ, sent to
the branches and then installed directly without additional configuration.

26.8 Configuring Device Mode (Router)

Click MAINTENANCE > Device Mode to open the following screen. Use this screen to
configure your ZyWALL as a router or a bridge.
In bridge mode, the ZyWALL functions as a transparent firewall (also known as a bridge
firewall). The ZyWALL bridges traffic traveling between the ZyWALL's interfaces and still
filters and inspects packets. You do not need to change the configuration of your existing
network.
In bridge mode, the ZyWALL cannot get an IP address from a DHCP server. The LAN, WAN,
DMZ and WLAN interfaces all have the same (static) IP address and subnet mask. You can
configure the ZyWALL's IP address in order to access the ZyWALL for management. If you
connect your computer directly to the ZyWALL, you also need to assign your computer a
static IP address in the same subnet as the ZyWALL's IP address in order to access the
ZyWALL.