Chapter 10 Firewalls
P-660HN-F1A User’s Guide
208
10.5.4.1 The “Triangle Route” Problem
A traffic route is a path for sending or receiving data packets between two
Ethernet devices. You may have more than one connection to the Internet
(through one or more ISPs). If an alternate gateway is on the LAN (and its IP
address is in the same subnet as the P-660HN-F1A’s LAN IP address), the “triangle
route” (also called asymmetrical route) problem may occur. The steps below
describe the “triangle route” problem.
1
A computer on the LAN initiates a connection by sending out a SYN packet to a
receiving server on the WAN.
2
The P-660HN-F1A reroutes the SYN packet through Gateway A on the LAN to the
WAN.
3
The reply from the WAN goes directly to the computer on the LAN without going
through the P-660HN-F1A.
As a result, the P-660HN-F1A resets the connection, as the connection has not
been acknowledged.
Figure 83
“Triangle Route” Problem
10.5.4.2 Solving the “Triangle Route” Problem
If you have the P-660HN-F1A allow triangle route sessions, traffic from the WAN
can go directly to a LAN computer without passing through the P-660HN-F1A and
its firewall protection.
Another solution is to use IP alias. IP alias allows you to partition your network
into logical sections over the same Ethernet interface. Your P-660HN-F1A supports
up to three logical LAN interfaces with the P-660HN-F1A being the gateway for
each logical network.
1
2
3
WAN
LAN
A
ISP 1
ISP 2
Summary of Contents for P-660HN-F1A
Page 2: ......
Page 10: ...Contents Overview P 660HN F1A User s Guide 10...
Page 20: ...Table of Contents P 660HN F1A User s Guide 20...
Page 21: ...21 PART I User s Guide...
Page 22: ...22...
Page 36: ...Chapter 2 Introducing the Web Configurator P 660HN F1A User s Guide 36...
Page 44: ...Chapter 3 Status Screens P 660HN F1A User s Guide 44...
Page 84: ...Chapter 4 Tutorials P 660HN F1A User s Guide 84 Physical Port 1 3 exclude port 4 3 Click Apply...
Page 88: ...Chapter 4 Tutorials P 660HN F1A User s Guide 88...
Page 103: ...103 PART II Technical Reference...
Page 104: ...104...
Page 142: ...Chapter 7 LAN Setup P 660HN F1A User s Guide 142...
Page 188: ...Chapter 9 Network Address Translation NAT P 660HN F1A User s Guide 188...
Page 210: ...Chapter 10 Firewalls P 660HN F1A User s Guide 210...
Page 236: ...Chapter 13 Certificates P 660HN F1A User s Guide 236...
Page 240: ...Chapter 14 Static Route P 660HN F1A User s Guide 240...
Page 276: ...Chapter 17 Dynamic DNS Setup P 660HN F1A User s Guide 276...
Page 288: ...Chapter 18 Remote Management P 660HN F1A User s Guide 288...
Page 344: ...Chapter 24 Troubleshooting P 660HN F1A User s Guide 344...
Page 376: ...Appendix A Setting up Your Computer s IP Address P 660HN F1A User s Guide 376...
Page 386: ...Appendix B Pop up Windows JavaScripts and Java Permissions P 660HN F1A User s Guide 386...
Page 396: ...Appendix C IP Addresses and Subnetting P 660HN F1A User s Guide 396...
Page 420: ...Appendix F Legal Information P 660HN F1A User s Guide 420...
Page 430: ...Index P 660HN F1A User s Guide 430...