
Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
Layer 2 and Layer 3 Firewalls
193
213455-L, October 2005
To configure a Layer 2 bridging firewall, follow this procedure on NSF#1 and then on NSF#2.
1.
Configure the bridge parameters on both firewalls.
Specify the ports participating in the bridging firewall. (Set the VLAN ID if the ports are used
by other interfaces.)
The configuration menu allows you to create up to 25 bridges. You can add any physical port
other than the SSI management port to these bridges. The bridge ID is the MAC address of one
of the physical interfaces added to the bridge.
N
OTE
–
If the SSI management interface is configured on a VLAN, the same VLAN cannot be
used for the bridge.
Failover support:
To support failover on Layer 2 firewalls, you must configure VRRP in one
of the following two ways:
Pure Layer 2 mode
: Configure at least one non-bridge interface with VRRP and a bridge
interface
without
VRRP and IP addresses.
Layer 2-Layer 3 mode
: Configure the bridge interface
with
VRRP and IP addresses as
follows:
addr1
and
addr2
in the #
cfg/net/bridge
menu
ip1
in the #
cfg/net/bridge/vrrp
menu
Configuring these addresses enables VRRP support on the bridge interface, but the
firewall functions in Layer 3 mode.
N
OTE
–
Nortel recommends defining multiple interfaces with VRRP. If a single interface is
configured as in Layer 2-Layer 3 mode, then failure of the interface breaks the cluster and
stops the functioning of Layer 2 firewall.
>> # /cfg/net/
bridge 1
Bridge 1#
ports
Bridge 1 Ports#
add 3
(Port 3 participates in the bridge)
Bridge 1 Ports#
add 4
(Port 4 participates in the bridge)
Bridge 1 Ports#
..
Bridge 1#
ena
(Enable the Layer 2 bridge)
Содержание 5100 Series Release 2.3.3
Страница 18: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 18 Preface 213455 L October 2005...
Страница 20: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 20 Getting started 213455 L October 2005...
Страница 28: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 28 Introduction 213455 L October 2005...
Страница 90: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 90 Initial setup 213455 L October 2005...
Страница 188: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 188 Redundant Firewalls 213455 L October 2005...
Страница 228: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 228 Applications 213455 L October 2005...
Страница 248: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 248 Basic system management 213455 L October 2005...
Страница 250: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 250 Command reference 213455 L October 2005...
Страница 264: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 264 The Command Line Interface 213455 L October 2005...
Страница 374: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 374 Command reference 213455 L October 2005...
Страница 376: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 376 Appendices 213455 L October 2005...
Страница 406: ...Nortel Switched Firewall 2 3 3 User s Guide and Command Reference 406 Common tasks 213455 L October 2005...