D-Link DFL-2500 User Guide - Page 111

Interface, Network, Gateway, ProxyARP, Source, Destination, Service, Forward, Return, Range

Page 111 highlights

92 Chapter 10. Routing • This is a "drop-in" design, where there are no explicit routing subnets between the ISP gateways and the firewall. In a provider-independent metropolitan area network, clients will likely have a single IP address, belonging to either one or the other ISP. In a single-organization scenario, publicly accessible servers will be configured with two separate IP addresses: one from each ISP. However, this difference does not matter for the policy routing setup itself. Note that, for a single organization, Internet connectivity through multiple ISPs is normally best done through BGP, where you do not need to worry about different IP spans or policy routing. Unfortunately, this is not always possible, and this is where policy based routing becomes a necessity. We will set up the main routing table to use ISP A, and add a named routing table, "r2" that uses the default gateway of ISP B. Contents of the main routing table: Interface LAN1 LAN1 WAN1 WAN2 WAN1 Network 1.2.3.0/24 2.3.4.0/24 1.2.3.1/32 2.3.4.1/32 0.0.0.0/0 Gateway 1.2.3.1 ProxyARP WAN1 WAN1 LAN1 LAN1 Contents of the named policy routing table r2: Interface Network Gateway WAN2 0.0.0.0/0 2.3.4.1 The table r2 has its Ordering parameter set to Default, which means that it will only be consulted if the main routing table lookup matches the default route (0.0.0.0/0). Contents of the Policy-based Routing Policy: Source Interface LAN1 WAN2 Source Range 2.3.4.0/24 0.0.0.0/0 Destination Interface WAN2 LAN1 Destination Range 0.0.0.0/0 2.3.4.0/24 Service ALL ALL Forward PBR r2 Return PBR r2 D-Link Firewalls User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365

92
Chapter 10. Routing
This is a ”drop-in” design, where there are no explicit routing subnets
between the ISP gateways and the firewall.
In a provider-independent metropolitan area network, clients will likely
have a single IP address, belonging to either one or the other ISP. In a
single-organization scenario, publicly accessible servers will be configured
with two separate IP addresses: one from each ISP. However, this difference
does not matter for the policy routing setup itself.
Note that, for a single organization, Internet connectivity through multiple
ISPs is normally best done through BGP, where you do not need to worry
about different IP spans or policy routing. Unfortunately, this is not always
possible, and this is where policy based routing becomes a necessity.
We will set up the main routing table to use ISP A, and add a named
routing table, ”r2” that uses the default gateway of ISP B.
Contents of the main routing table:
Interface
Network
Gateway
ProxyARP
LAN1
1.2.3.0/24
WAN1
LAN1
2.3.4.0/24
WAN1
WAN1
1.2.3.1/32
LAN1
WAN2
2.3.4.1/32
LAN1
WAN1
0.0.0.0/0
1.2.3.1
Contents of the named policy routing table r2:
Interface
Network
Gateway
WAN2
0.0.0.0/0
2.3.4.1
The table r2 has its Ordering parameter set to Default, which means that it
will only be consulted if the main routing table lookup matches the default
route (0.0.0.0/0).
Contents of the Policy-based Routing Policy:
Source
Source
Destination
Destination
Service
Forward
Return
Interface
Range
Interface
Range
PBR
PBR
LAN1
2.3.4.0/24
WAN2
0.0.0.0/0
ALL
r2
<
main
>
WAN2
0.0.0.0/0
LAN1
2.3.4.0/24
ALL
<
main
>
r2
D-Link Firewalls User’s Guide