SonicOSX 7 System

Configuring WAN Interfaces

A default gateway IP is required on the WAN interface if any destination is required to be reached through the WAN interface that is not part of the WAN subnet IP address space, regardless whether we receive a default route dynamically from a routing protocol of a peer device on the WAN subnet.

Configuring a WAN interface enables Internet connectivity. You can configure up to N minus 2 WAN interfaces on the appliance, where N is the number of interfaces defined on the unit (both physical and VLAN). Only X0 and MGMT interfaces cannot be configured as WAN interfaces.

To configure your WAN interface

  1. Navigate to NETWORK | System > Interfaces.
  2. Click on the Edit icon in the Configure column for the Interface you want to configure. The Edit Interface dialog displays.
  3. If you are configuring an unassigned Interface, select WAN from the Zone menu. If you selected the Default WAN interface, WAN is already selected in the Zone menu.
  4. Select one of the following WAN Network Addressing Modes from IP Assignment.

    Depending on the option you choose from the IP Assignment drop-down menu, the options available change. Complete the corresponding fields that are displayed after selecting the option.

    • Static - configures the appliance for a network that uses static IP addresses.
    • DHCP - configures the appliance to request IP settings from a DHCP server on the Internet. NAT with DHCP Client is a typical network addressing mode for cable and DSL customers.
    • PPPoE - uses Point to Point Protocol over Ethernet (PPPoE) to connect to the Internet. If a username and password is required by your ISP, enter them into the User Name and User Password fields. This protocol is typically found when using a DSL modem.
    • PPTP - uses PPTP (Point to Point Tunneling Protocol) to connect to a remote server. It supports older Microsoft Windows implementations requiring tunneling connectivity.
    • L2TP - uses IPsec to connect a L2TP (Layer 2 Tunneling Protocol) server and encrypts all data transmitted from the client to the server. However, it does not encrypt network traffic to other destinations.
    • Tap Mode (1-Port Tap) - allows insertion of the appliance into a network for use with network taps, port mirrors, or SPAN ports. For detailed information, see Configuring Wire and Tap Mode.
    • Wire Mode (2-Port Wire) - allows insertion of the appliance into a network, in Bypass, Inspect, or Secure mode. For detailed information, see Configuring Wire and Tap Mode.
    • Static One Arm Mode - only one firewall interface with a static IP address is used, and all traffic comes into and out from the same interface. See Configuring One Arm Mode.
    • DHCP One Arm Mode - only one firewall interface with a DHCP IP address is used, and all traffic comes into and out from the same interface. See Configuring One Arm Mode.
  5. If using DHCP, optionally enter a descriptive name in the Host Name field and any desired comments in the Comment field.
  6. If using PPPoE, PPTP, or L2TP, additional fields display:
    • If Schedule is displayed, select the desired schedule from the drop-down menu during which this interface should be connected.
    • In User Name and User Password, type in the account name and password provided by your ISP.
    • If the Server IP Address field is displayed, enter the server IP address provided by your ISP.
    • If the (Client) Host Name field is displayed, enter the host name of the appliance. This is the firewall name from System > Administration | Firewall Administrator.
    • If the Shared Secret field is displayed, enter the value provided by your ISP.
  7. If you want to enable remote management of the appliance from this interface, select the supported management protocol(s): HTTPS, Ping, SNMP, and/or SSH.
    • To allow access to the WAN interface for management from another zone on the same appliance, access rules must be created. For information about creating access rules, see SonicOS Policies Administration Guide.
  8. If using PPPoE, PPTP, or L2TP, additional fields display:
    • For PPPoE, choose one of the following:

      • Obtain IP Address Automatically to get the IP address from the PPPoE server.
      • Specify IP Address and enter the desired IP address into the field to use a static IP address for this interface.
      • Unnumbered interface and either:

        • Select an unnumbered interface.
        • Create a new unnumbered interface by selecting Create new Unnumbered Interface.

        The interface must be unassigned.

    • For PPTP or L2TP, configure these options:

      • From IP Assignment, select either:

        • DHCP; the IP Address, Subnet Mask, and Gateway Address fields are automatically provisioned by the server.
        • Static, enter the appropriate values for these fields.
      • Select Inactivity Disconnect and enter the number of minutes of inactivity after which the connection is terminated. Clear this option to disable inactivity timeouts.
  9. If using DHCP, optionally choose:

    • Request renew of previous IP on startup to request the same IP address for the WAN interface that was previously provided by the DHCP server.
    • Renew DHCP lease on any link up occurrence to send a lease renewal request to the DHCP server every time this WAN interface reconnects after being disconnected.

    The fields displayed below these options are provisioned by the DHCP server. After provisioning, these buttons are available; choose:

    • Renew to restart the DHCP lease duration for the currently assigned IP address.
    • Release to cancel the DHCP lease for the current IP address. The connection is dropped. You need to obtain a new IP address from the DHCP server to reestablish connectivity.
    • Refresh to obtain a new IP address from the DHCP server.
  10. To allow selected users with limited management rights to log directly into the appliance from this interface, select HTTP and/or HTTPS in User Login.
  11. Check Add rule to enable redirect from HTTP to HTTPS, if you want an HTTP connection automatically redirected to a secure HTTPS connection to the appliance. For more information about this option, see HTTP/HTTPS Redirection.
  12. Continue the configuration on the Advanced and Protocol tabs (if displayed) as described in Configuring Advanced Settings for a WAN Interface.
  13. To continue with Advanced settings; go to Configuring Advanced Settings for a WAN Interface.
  14. If you selected PPPoE, PPTP, or L2TP for IP Assignment, go to Configuring Protocol Settings for a WAN Interface.
  15. Click OK.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden