Coyote Point Systems Equalizer Especificaciones Pagina 91

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 594
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 90
-> 10.0.0.0/24
0.0.0.0/0
7: pass on interface wm0 hits: 4 bytes: 756
From To
10.0.0.0/24 -> any
8: pass on interface wm1 hits: 0 bytes: 0
From To
any -> 192.168.211.0/24
9: pass on interface wm0 hits: 0 bytes: 0
From To
any -> 10.0.0.0/24
0.0.0.0/0
10: block all hits: 1 bytes: 328
It can also be verified using the traceroute tool, available in most Operating Systems. If a traceroute is performed
from the server, a different second-hop gateway is used than the first-hop gateway on the Equalizer traceroute:
freebsd# traceroute 64.13.152.126
traceroute to 64.13.152.126 (64.13.152.126), 64 hops max, 40 byte
packets
1 192.168.211.8 (192.168.211.8) 0.576 ms 0.799 ms 0.241 ms
2 192.168.211.2 (192.168.211.2) 0.522 ms 0.547 ms 0.334 ms
EQUALIZER# traceroute -n 64.13.152.126
traceroute to 64.13.152.126 (64.13.152.126), 64 hops max, 40 byte
packets
1 192.168.8.2 1.653 ms 1.342 ms 1.225 ms
In the example above, the server ("freebsd") uses the Equalizer (192.168.211.8) as its gateway, and the Equalizer
sends the packet on the 192.168.211.2 gateway. However, when the Equalizer performs a traceroute to the same
location, it uses the 192.168.8.2 gateway.
Dual VLAN/Network with Outbound NAT
If we start with the configuration in Dual VLAN/Network, it should be noted that this configuration is not sufficient if
the servers on the internal network require Internet connectivity. Equalizer will properly send traffic from the
internal network to the Internet, but because the internal network is non-routable, hosts on the Internet will not be
able to respond. One way to solve this problem is to have a separate NAT gateway for the server network, as
described in Dual VLAN/Network with 2 Gateways. However, because most locations have a single outbound
link, configurations with only a single gateway must use Outbound NAT.
Note - The Outbound NAT feature is not available for IPv6 on Equalizer.
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
All Rights Reserved.
91
Equalizer Administration Guide
Vista de pagina 90
1 2 ... 86 87 88 89 90 91 92 93 94 95 96 ... 593 594

Comentarios a estos manuales

Sin comentarios