
WANGUARD 5.2 User Manual & Administrator's Guide
The Layer-2 Forwarding (L2F) method is used in a Layer 2 topology when all three devices—the Filter
system, the divert-from router, and the next-hop router—are located in one shared IP network. In a Layer 2 topology,
a divert-from router and an inject-to router are two separate devices. The next-hop router and the inject-to router
are the same device.
The Filter system issues an ARP query to resolve the MAC address of the inject-to/next-hop router and then
forwards the trafc. For this reason, no confguraton on the routers is required when using the L2F method. The
only thing you have to confgure when using this method is the default gateway on the Filter system so that it points
to the inject-to/next-hop router.
Configuring GRE / IP over IP Tunneling – Layer 3 Forwarding Method
In the tunnel diversion method, you confgure a tunnel between the Filter server and each of the next-hop
routers. The Filter's server sends the trafc over the tunnel that ends in the next-hop router of the destned zone.
Because the returned trafc goes over a tunnel, the inject-to router performs a routng decision on the end point of
the tunnel interface only, not on the zone’s address.
To use this method you have to run the standard Linux tool
ip
to create and route GRE / IP over IP tunnels
that will be used to inject the cleaned trafc back into the network. You must then confgure the Filter ( page 53 )
with the Outbound Interface set to the virtual network interface created by the tunnel.
- 72 -
Содержание Wanguard 5.2
Страница 1: ......