Bridging |
Top Previous Next |
At this form you can connect two or more network interfaces to a bridge. A bridge connects two or more network segments on layer 2 of the ISO/OSI model. The firewall is a so called MAC bridge which means that the firewall stores the MAC addresses of all devices connected to the bridge interfaces. If a request for a special MAC address in this table is coming in it is forwarded to the correct network interface of the bridge. By using a bridge the firewall can be used transparently at the layer 3 (IP layer) of the ISO/OSI model and can forward an official IP to an internal server without even recognizing the existence of the firewall. Nevertheless the traffic is filtered and checked. Because the traffic is crossing the interfaces transparently, no routing or NAT is needed. The bridges are mostly used when the firewall works as a transparent traffic shaper or as a transparent intrusion detection system (IDS) because it can be integrated in an existing network very easily. Nothing must be changed at the existing infrastructure.
ATTENTION: Use bridging of two or more network interfaces only if you completely understand the logic of the technique. Improper use of this service can lead to security vulnerabilities.
NOTE: Creating the bridge after clicking the button Save can take a few minutes. Please be patient.
|