D-Link DFL-2500 User Guide - Page 109

Create PBR Table, Routing, Policy-based Routing Tables, Policy-based Routing Table, Ordering, First

Page 109 highlights

90 Chapter 10. Routing rules. The first matching rule will be the one to use. According to the specification in the rule, a routing table is selected to use. If there is no matching rule, the PBR tables will not be used and nor PBR will be performed. The firewall will forward the packets according to the main routing table only. 4. Address translation - If SAT rule was encountered in the rules consulting in step 2, address translation will be performed. 5. Final route lookup and packet forwarding - the firewall makes the final route lookup in the routing table decided in step 3, and forward the packet. The decision of which routing table to use is made before carrying out address translation. However, the actual route lookup is performed on the altered address. Example: Creating a Policy-Based Routing Table In this example we create a policy-based routing table named "TestPBRTable". WebUI : Create PBR Table Routing → Policy-based Routing Tables → Add → Policy-based Routing Table: Name: TestPBRTable Ordering: First - means that the named routing table is consulted first of all. If this lookup fails, the lookup will continue in the main routing table. Default - means that the main routing table will be consulted first. If the only match is the default route (0.0.0.0/0), the named routing table will be consulted. If the lookup in the named routing table fails, the lookup as a whole is considered to be failed. Only - means that the named routing table is the only one consulted. If this lookup fails, the lookup will not continue in the main routing table. Remove Interface IP Routes: If enabled, the default interface routes are removed, i.e. routes to the core interface, which are routes to the firewall itself. Then click OK D-Link Firewalls User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365

90
Chapter 10. Routing
rules. The first matching rule will be the one to use. According to the
specification in the rule, a routing table is selected to use. If there is
no matching rule, the PBR tables will not be used and nor PBR will
be performed. The firewall will forward the packets according to the
main routing table only.
4. Address translation – If SAT rule was encountered in the rules
consulting in step 2, address translation will be performed.
5. Final route lookup and packet forwarding – the firewall makes the
final route lookup in the routing table decided in step 3, and forward
the packet.
The decision of which routing table to use is made before carrying out
address translation. However, the actual route lookup is performed on the
altered address.
Example
:
Creating a Policy-Based Routing Table
In this example we create a policy-based routing table named
”TestPBRTable”.
WebUI
:
Create PBR Table
Routing
Policy-based Routing Tables
Add
Policy-based Routing Table:
Name:
TestPBRTable
Ordering:
First
- means that the named routing table is consulted first of all. If this
lookup fails, the lookup will continue in the main routing table.
Default
- means that the main routing table will be consulted first. If the
only match is the default route (0.0.0.0/0), the named routing table will be
consulted.
If the lookup in the named routing table fails, the lookup as a
whole is considered to be failed.
Only
- means that the named routing table is the only one consulted.
If
this lookup fails, the lookup will not continue in the main routing table.
Remove
Interface
IP
Routes:
If
enabled,
the
default
interface
routes are removed, i.e. routes to the
core
interface, which are routes to the
firewall itself.
Then click
OK
D-Link Firewalls User’s Guide