Networking Translation Between EQ/OS 10.1.x and 10.2.x
Networking Translation Between 10.1.x and 10.2.x Systems
Several, significant networking enhancements were made as part of EQ/OS 10.2.x development.
These include:
1. Per-subnet static routes have been enhanced to allow the user to specify an optional source
IP address.
l
If no source is specified, the static route applies to all traffic originating from the entire sub-
net.
l
If a source is specified, the static route applies only to traffic originating from the IP
address range specified by the source IP parameter (in CIDR format).
This allows the user to restrict routes to a specific IP address range or a single IP address.
2. The subnet
outbound_nat
parameter has been removed. It is replaced by enhanced Network
Address Translation (NAT) capabilities that allow the user to specify an IP address range (or
a single IP) and the IP address that will be used as the source IP for outgoing packets on an
interface. NAT rules (like static routes) are specified on a per-subnet basis, providing
flexibility when configuring routing. Additional information on NAT can be found in
3. The
default_route
(Default Route) subnet parameter used in 10.1.x configurations has been
removed.
4. The
def_src_addr
(Default Source Address) flag used in 10.1.x configurations has been
removed.
5. Destination networks used in 10.1.x configurations have been removed. Destination
networks are now computed automatically by the system according to the static route
configuration. No user configuration is needed. In order for destination networks to be
properly computed, static routes must be configured as follows:
If a gateway provides internet connectivity, a static route should be configured with
destination 0/0. If a gateway does not provide internet connectivity, a separate static route
should be configured for each network reachable via the gateway..
The table below itemizes specific EQ/OS 10.1.x networking configuration scenarios and describes
how they translate to the EQ/OS 10.2.x enhancements in an upgrade. In general:
l
The
default_route
subnet parameter is translated to a static route with a 0/0 destination
(0.0.0.0/0) in a 10.2.x configuration.
l
The
outbound_nat
subnet parameter is translated to a subnet NAT rule which NATs the entire
subnet range out the
outbound_nat
IP address.
l
When a misconfiguration is detected that results in the new configuration possibly working
differently than the old configuration, an error is logged to
/var/log/eq
, as well as the system
console. This error will appear after rebooting the system after the upgrade.
844
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......