SonicOSX 7 System

Perimeter Security

Perimeter Security is a network scenario where the appliance is added to the perimeter to provide security services (the network might or might not have an existing appliance between the appliance and the router). In this scenario, everything below the appliance (the Primary Bridge Interface segment) is generally considered as having a lower level of trust than everything to the left of the appliance (the Secondary Bridge Interface segment). For that reason, it would be appropriate to use X1 (Primary WAN) as the Primary Bridge Interface.

Traffic from hosts connected to the Secondary Bridge Interface (LAN) would be permitted outbound through the firewall to their gateways (VLAN interfaces on the L3 switch and then through the router), while traffic from the Primary Bridge Interface (WAN) would, by default, not be permitted inbound.

If there are public servers, for example, a mail and Web server, on the Secondary Bridge Interface (LAN) segment, an Access Rule allowing WAN > LAN traffic for the appropriate IP addresses and services could be added to allow inbound traffic to those servers.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden