Configuration Options
Using traffic diversion in service provider environment
FortiDDoS v3.2 Installation Guide
28-320-183686-20130401
24
•
Configuring the bypass switch
A 10/100/1000 bypass switch allows you to set communication parameters. Refer to
the
FortiGate Hardware Guide
to set the following parameters:
•
Auto-negotiation
•
Line speed
•
Link Fault Detect (LFD)
•
Input timeout period
•
Input retry count
Connecting the 10/100/1000 bypass switch to the network
1
Connect the INT 1 port to the Server side.
2
Connect the EXT 1 port to the Internet side.
3
Connect the INT 2 port to the Server Port of the FortiDDoS device.
4
Connect the EXT 2 port to the Internet Port of the FortiDDoS device.
Configuring MAC Addresses for Bypass Switch Heatbeat Packets
When a FortiDDoS appliance is used in conjunction with a bypass switch such as
FortiBridge, you have to ensure that heartbeat packets from the bypass switch are
allowed in Prevention Mode under all possible cases of packets being blocked by the
FortiDDoS.
Typically all bypass switches use heartbeat packets to check if the data path is
connected. If the data path is broken for some critical reason, the bypass switch
switches to bypass mode from normal mode.
To ensure passage of the heartbeat packets, FortiDDoS allows you to configure the
MAC addresses of the bypass switch. These MAC addresses are used by the bypass
switch for the heartbeat packets.
FortiBridge appliance allows you to view the MAC addresses in the status page.
Every FortiDDoS link pair can be connected via a FortiBridge link pair. E.g. LAN1,
WAN1 can be bridged via a FortiBridge link and LAN2, WAN2 on a card can be
similarly bridged via another FortiBridge link. Each of these link pairs will be associated
with a pair of MAC addresses. Therefore if you are using two links you will need to
configure 4 MAC addresses. If you are using one link then you need to specify just one
pair of MAC addresses.
To configure, please refer to section “Configuring MAC Addresses for Bypass Switch
Heatbeat Packets” in the
FortiDDoS Web-based Manager v3.1 Reference Guide
.
Using traffic diversion in service provider environment
Traffic diversion
A FortiDDoS device can be deployed in Service Provider environment where the total
bandwidth may be much more than what the appliance can support, but the attack
traffic to a specific subnet or server is within its capacity. In such cases, normal traffic
is sent through its regular path while the attack traffic is manually diverted by Service
Provider staff during attack through the FortiDDoS device. The FortiDDoS device in
turn cleans the traffic and injects it back to the network.
Содержание FortiDDoS
Страница 1: ...FortiDDoS v3 2 Installation Guide ...
Страница 37: ......