D-Link DFL-700 Product Manual - Page 126

SYSTEM, ROUTING, Add New, Network, Subnet Mask, Proxy ARP, Apply, Example Scenario using DMZ w/out NAT

Page 126 highlights

Example Scenario using DMZ w/out NAT: An alternative method to that described in the preceding pages is to isolate publicly accessible servers to the DMZ interface with NAT disabled. This configuration requires multiple (at least 2) Public IP addresses to function, as the Firewall will assume one IP and the Server(s) will use the other(s). Configure the Static Routes: A new route must be added to inform the firewall on which interface the Public IP will reside. Navigate to SYSTEM > ROUTING in the web-based configuration of the DFL-700. Click on Add New to create a new static route. Select DMZ as the Interface. Enter the IP Address (WAN Network) you wish to forward to a server on the DMZ interface in the Network field. Select a 32-bit subnet mask from the Subnet Mask dropdown box. Be sure to have Proxy ARP enabled by checking the checkbox. Click Apply to save any changes. 126

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138

126
Example Scenario using DMZ w/out NAT:
An alternative method to that described in the preceding pages is to isolate publicly
accessible servers to the DMZ interface with NAT disabled.
This configuration requires
multiple (at least 2) Public IP addresses to function, as the Firewall will assume one IP and
the Server(s) will use the other(s).
Configure the Static Routes:
A new route must be added to inform the firewall on which interface the Public IP will reside.
Navigate to
SYSTEM
>
ROUTING
in the web-based configuration of the DFL-700.
Click on
Add New
to create a new static route.
Select
DMZ
as the Interface.
Enter the IP Address (WAN Network) you wish to forward
to a server on the
DMZ
interface in the
Network
field.
Select a 32-bit subnet mask from the
Subnet Mask
dropdown box.
Be sure to have
Proxy ARP
enabled by checking the checkbox.
Click
Apply
to save any changes.