. . . . .
S E C U R I T Y Z O N E S A N D I N T E R F A C E S
Configuring Interface Modes
Version 3R2
Security Appliance User Guide
3-19
To further secure management traffic, an additional VLAN network is
created solely for management access. This is done by creating a sub-
interface for br0. In this scenario we will create a VLAN called br0.5.
Figure 3-10: Transparent Mode with VLAN Filtering
In
Figure 3-10
the freeGuard Blaze 2100 will be in Transparent mode
with multiple VLAN interfaces and Zones. This will give an administrator
the ability to filter various source/dest address's/zones based on the
VLAN ID.
CLI Configuration
set interface eth0 ip 0.0.0.0/0
set interface eth0 transparent
set interface eth0 zone trust
set interface eth1 ip 0.0.0.0/0
Routed Mode
L2 Switch
802.1q-Trunk Port
VLAN 100-500
802.1q Trunk Port
VLAN 100-500
&
VLAN 5
VLAN/Zone Table
VLAN br0.5: 10.2.1.0/24
Zone: ManageNet
VLAN 100: 10.0.1.0/24
Zone: Engineering
VLAN 200: 192.168.100.0/24 Zone: Accounting
VLAN 300 : 192.168.200.0/24 Zone: Finance
VLAN 400 : 172.27.16.0/24 Zone: Lab
VLAN 500: 10.0.200.0/24
Zone: Sales
VLAN 200
Accounting
VLAN 300
Finance
VLAN 400
Lab
VLAN 500
Sales
VLAN 100
Engineering
Eth: br0.5 Management
10.2.1.1/24 Zone
ManageNet
Eth1: Untrust
Eth0: Trust
VLAN 5
Management Net