Juniper Networks IDP250, IDP8200, IDP 800 Proxy-ARPMode, IDP High Availability Deployment Modes

Models: IDP250

1 68
Download 68 pages 1.06 Kb
Page 60
Image 60
Proxy-ARP Mode

IDP 75, 250, 800, and 8200 Installation Guide

Proxy-ARP Mode

Figure 23 shows a sensor that is configured in bridge mode. Table 16 lists the advantages and disadvantages of bridge mode.

Figure 23: Proxy-ARP Mode

 

Internet

 

 

Firewall

 

Hub or

IP 2.2.2.1

Switch

 

 

 

 

 

 

IP 1.1.1.1

 

 

 

eth2

 

 

 

IP 1.1.1.254

 

 

IDP Sensor

Forwarding Interface

Management Server

 

 

 

 

 

 

IP 2.2.2.4

eth0 IP 2.2.2.7

eth3

 

 

MGT Interface

IP 1.1.1.5

 

 

 

Forwarding Interface

 

Hub or

 

 

Switch

 

 

 

 

 

User Interface

 

 

 

IP 2.2.2.5

Server1

Server2

Server3

 

IP 1.1.1.2

IP 1.1.1.3

IP 1.1.1.4

 

GW 1.1.1.1

GW 1.1.1.1

GW 1.1.1.1

 

 

Protected Machines

 

 

Table 16: Advantages and Disadvantages of Proxy-ARP Mode

Advantages

Disadvantages

 

 

„ Reliably responds to and prevents

„ Network nodes may need to update

attacks

cached ARP entries

„Simple, transparent deployment

IDP High Availability Deployment Modes

You must deploy the IDP sensors in bridge, router, transparent, or proxy-ARP mode to enable a high availability solution.For details on deployment modes and HA clusters, see the NetScreen-Security Manager Administrator’s Guide.

46„ IDP High Availability Deployment Modes

Page 60
Image 60
Juniper Networks IDP250, IDP8200, IDP 800, IDP75 manual Proxy-ARPMode, IDP High Availability Deployment Modes