Chapter 15 Firewall
1A computer on the LAN initiates a connection by sending out a SYN packet to a receiving server on the WAN.
2The
3The reply from the WAN goes directly to the computer on the LAN without going through the
As a result, the
Figure 95 “Triangle Route” Problem
LANWAN
1
ISP 1
|
|
|
|
|
|
|
|
|
3 |
|
|
| 2 |
|
| ||
|
|
|
|
| ||||
|
|
|
|
| ||||
|
|
|
|
| ||||
|
|
|
|
| ||||
|
|
|
|
| ||||
|
|
|
|
| ||||
|
|
|
|
|
ISP 2
A
15.6.4.2 Solving the “Triangle Route” Problem
If you have the
Another solution is to use IP alias. IP alias allows you to partition your network into logical sections over the same Ethernet interface. Your
It’s like having multiple LAN networks that actually use the same physical cables and ports. By putting your LAN and Gateway A in different subnets, all returning network traffic must pass through the
1A computer on the LAN initiates a connection by sending a SYN packet to a receiving server on the WAN.
2The
3The reply from the WAN goes to the
4The
184 |
|
|
|