Installation Topics

This table shows you the ports you must open on a desktop firewall.

Server Type/Appliance Software

Protocol/Port

Management Server

TCP 4109, TCP 4110, TCP 4112, TCP 4113

 

 

Log Server

 

with Fireware appliance software

TCP 4115

with WFS appliance software

TCP 4107

 

 

WebBlocker Server

TCP 5003, UDP 5003

 

 

WFS appliance software configuration modes

There are two configuration modes available for users with WFS appliance software: a routed configura- tion or a drop-in configuration. (If you are using Fireware appliance software, drop-in mode is not avail- able.) Many networks operate the best with a routed configuration. But we recommend the drop-in mode if:

You have a large number of public IP addresses

You have a static external IP address

You cannot configure the computers on your trusted and optional networks that have public IP addresses with private IP addresses

The table below shows three conditions that can help you to select a firewall configuration mode. We then give more information about each mode.

 

Routed Configuration

Drop-in Configuration

Condition 1

All interfaces of the Firebox are on

All interfaces of the

 

different networks. The minimum

Firebox are on the same

 

configured interfaces are external and

network and have the same

 

trusted.

IP address (Proxy ARP).

 

 

 

Condition 2

Trusted and optional interfaces must be

The computers on the

 

on different networks. The two interfaces

trusted or optional

 

must have an IP address on their

interfaces can have a

 

respective network.

public IP address.

 

 

 

Condition 3

Use static NAT to map public addresses

The machines that have

 

to private addresses behind the trusted

public access have public

 

or optional interfaces.

IP addresses. Thus, no

 

 

static NAT is necessary.

 

 

 

Routed configuration

You use the routed configuration when you have a small number of public IP addresses or when your Firebox gets its external IP address using PPPoE or DHCP. This configuration also makes it easier to con- figure virtual private networks.

User Guide

9

Page 15
Image 15
WatchGuard Technologies Firebox X manual WFS appliance software configuration modes, Routed configuration