3
Chapter3 Installation
55
Static IP address that uses a private IP address
You need to set NAT to connect to the Internet from the sub-network.
Bridge Mode
When the cable model on the top provides DHCP service, TrusGuard can be used in bridge mode.
Set bridge mode, using an interface to connect the top and sub-network.
Set the DHCPv4 relay.
For connection using xDSL, you can you more than 2 xDSL for network availability.
Set the Load-Balancing.
When using TrusGuard as an IPSec VPN gateway, use the multipath settings.
Adjust the TCP MSS.
Operation Mode
TrusGuard operation mode is divided into Router Mode and Bridge Mode
Operating in Router Mode
The sub-network host uses the IP address given to the botton network interface of TrusGuard as the
gateway.
Operating in Bridge Mode
If you use an IP address for the bridge, the bridge interface becomes the gateway. If there is no IP
address, the router’s IP address can be used as the gateway. If there is no IP address for the bridge
interface, it is called a transparent bridge.
If you use a transparent bridge, you cannot use services that depend on network interface IP address.
You need a secondary port to use network port based NAT.
SSL VPN connection
IPSec VPN connection
Firewall Policy: To apply proxy, use the Transparent Proxy option.
HA
All the instructions above apply when TrusGuard is used solely. When using HA Mode, the settings will
be different. For more details, refer to the HA Mode section.
Jumbo Frame
Jumbo frame processes packets bigger than 1,500 bytes. To check or change the jumbo frame settings,
use the
get_jumbo_frame
and
set_jumbo_frame
commands in a terminal.