ZyXEL P-660HW-T1 v3 User Guide - Page 208
The Triangle Route Problem, 5.4.2, Solving the Triangle Route Problem
View all ZyXEL P-660HW-T1 v3 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 208 highlights
Chapter 10 Firewalls 10.5.4.1 The "Triangle Route" Problem A traffic route is a path for sending or receiving data packets between two Ethernet devices. You may have more than one connection to the Internet (through one or more ISPs). If an alternate gateway is on the LAN (and its IP address is in the same subnet as the ZyXEL Device's LAN IP address), the "triangle route" (also called asymmetrical route) problem may occur. The steps below describe the "triangle route" problem. 1 A computer on the LAN initiates a connection by sending out a SYN packet to a receiving server on the WAN. 2 The ZyXEL Device reroutes the SYN packet through Gateway A on the LAN to the WAN. 3 The reply from the WAN goes directly to the computer on the LAN without going through the ZyXEL Device. As a result, the ZyXEL Device resets the connection, as the connection has not been acknowledged. Figure 85 "Triangle Route" Problem LAN WAN 1 ISP 1 3 2 ISP 2 A 10.5.4.2 Solving the "Triangle Route" Problem If you have the ZyXEL Device allow triangle route sessions, traffic from the WAN can go directly to a LAN computer without passing through the ZyXEL Device and its firewall protection. Another solution is to use IP alias. IP alias allows you to partition your network into logical sections over the same Ethernet interface. Your ZyXEL Device supports up to three logical LAN interfaces with the ZyXEL Device being the gateway for each logical network. 208 P-660HW-Tx v3 Series User's Guide