D-Link DFL-2500 User Guide - Page 100

Dynamic Routing Implementation

Page 100 highlights

10.5. Dynamic Routing Implementation 81 10.5 Dynamic Routing Implementation In D-Link firewalls, the implementation of dynamic routing involves two primary configuration tasks: OSPF process & dynamic routing policy. 10.5.1 OSPF Process OSPF process configured in the firewall groups OSPF participating firewalls and routers into OSPF areas. Each process enabled on a router is given a unique Router ID in an IP address format and an authentication method is chosen. The areas are defined on the basis of the firewall's interfaces. An interface that belongs to an area has a Routing Priority to be used for the area's DR election. The interface can either be used for broadcast, point-to-point, or point-to-multipoint communication. The broadcast interface learns neighboring routers automatically by flooding "Hello" packets, while for point-to-point or point-to-multipoint interface, one or more specific neighbors need to be configured for the interface manually. Routing metrics used for OSPF can also be set or modified on an interface to interfere in the OSPF path determination. Once the OSPF process is properly configured for the firewall, it can begin to talk with other firewalls/routers using OSPF algorithm, and learn the link-state information of the network. 10.5.2 Dynamic Routing Policy Based on the routing information learned by the OSPF process, dynamic routing policy forms a filter to the information and tells the firewall what to do with those knowledge by defined actions. A Dynamic Routing Policy rule filters statically configured or OSPF learned routes according to parameters like the origin of the routes, destination, metric, and etc. The matched routes can be controlled by the actions to be either exported to OSPF processes or to be added to one or more routing tables. The most common usages of Dynamic Routing Policy are listed as follows, examples are given next. • Importing OSPF routes from OSPF process into the routing table. D-Link Firewalls User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365

10.5. Dynamic Routing Implementation
81
10.5
Dynamic Routing Implementation
In D-Link firewalls, the implementation of dynamic routing involves two
primary configuration tasks:
OSPF process
&
dynamic routing policy
.
10.5.1
OSPF Process
OSPF process configured in the firewall groups OSPF participating
firewalls and routers into OSPF areas. Each process enabled on a router is
given a unique
Router ID
in an IP address format and an
authentication
method
is chosen.
The areas are defined on the basis of the firewall’s interfaces. An interface
that belongs to an area has a
Routing Priority
to be used for the area’s
DR
election
. The interface can either be used for
broadcast
,
point-to-point
, or
point-to-multipoint
communication. The broadcast interface learns
neighboring routers automatically by flooding ”Hello” packets, while for
point-to-point or point-to-multipoint interface, one or more specific
neighbors need to be configured for the interface manually.
Routing metrics
used for OSPF can also be set or modified on an interface to interfere in the
OSPF path determination.
Once the OSPF process is properly configured for the firewall, it can begin
to talk with other firewalls/routers using OSPF algorithm, and learn the
link-state information of the network.
10.5.2
Dynamic Routing Policy
Based on the routing information learned by the OSPF process, dynamic
routing policy forms a filter to the information and tells the firewall what to
do with those knowledge by defined actions.
A
Dynamic Routing Policy rule
filters statically configured or OSPF
learned routes according to parameters like the origin of the routes,
destination, metric, and etc. The matched routes can be controlled by the
actions
to be either exported to OSPF processes or to be added to one or
more routing tables.
The most common usages of Dynamic Routing Policy are listed as follows,
examples are given next.
Importing OSPF routes from OSPF process into the routing table.
D-Link Firewalls User’s Guide