Previous Topic

Next Topic

Book Contents

Book Index

Overview

The UTM-1 appliance enables you to connect multiple network segments at the data-link layer, by configuring a bridge. Bridges offer the following advantages:

Linked Diagram Template

Bridge with Four VLANs

For example, if you assign the LAN and primary WLAN networks to a bridge and disable the bridge's internal firewall, the two networks will act as a single, seamless network, and only traffic from the LAN and primary WLAN networks to other networks (for example, the Internet) will be inspected by the firewall. If you enable the internal firewall, it will enforce security rules and inspect traffic between the LAN and primary WLAN networks.

Linked Diagram Template

Bridge Firewalling

The UTM-1 appliance allows you to configure anti-spoofing for bridged network segments. When anti-spoofing is configured for a segment, only IP addresses within a specific IP address range can be sent from that network segment. For example, if you configure anti-spoofing for the “Marketing” network segment, the following things happens:

Note: The following UTM-1 models do not support using bridge mode with port-based VLAN:

  • SBX166-LHGE-2
  • SBX166-LHGE-3

In This Section

How Does Bridge Mode Work?

Multiple Bridges and Spanning Tree Protocol

See Also

Using Bridges

Workflow

Adding and Editing Bridges

Adding Internal Networks to Bridges

Adding Internet Connections to Bridges

Deleting Bridges