Page 71 / 469 Scroll up to view Page 66 - 70
IPv4 and IPv6 Internet and WAN Settings
71
ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308
Note:
The default time to roll over after the primary WAN interface has
failed is 2
minutes. The minimum test period is 30 seconds, and the
minimum number of tests is 2.
6.
Click
Apply
to save your settings.
You can configure the VPN firewall to generate a WAN status log and email this log to a
specified address (see
Configure Logging, Alerts, and Event Notifications
on page
362).
Configure Advanced WAN Options and Other Tasks
The advanced options include configuring the maximum transmission unit (MTU) size, port
speed, and VPN firewall’s MAC address, and setting a rate limit on the traffic that is being
forwarded by the VPN firewall. You can also configure the failure detection method for the
auto-rollover mode.
Note:
Although you can access the WAN Advanced Options screen for a
WAN interface only through the WAN IPv4 ISP Settings screen, the
advanced options apply to both IPv4 and IPv6 WAN connections.
However, the failure detection method applies only to IPv4 settings.
To configure advanced WAN options:
1.
Select
Network Configuration > WAN Settings > WAN Setup
. In the upper right of the
screen, the IPv4 radio button is selected by default. The WAN Setup screen displays the
IPv4 settings:
Figure 44.
2.
Click the
Edit
table button in the Action column of the WAN interface for which you want to
configure the advanced WAN options. The WAN IPv4 ISP Settings screen displays. (The
following figure shows the WAN2 IPv4 ISP Settings screen as an example.)
Page 72 / 469
IPv4 and IPv6 Internet and WAN Settings
72
ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308
Figure 45.
3.
Click the
Advanced
option arrow in the upper right of the screen. The WAN Advanced
Options screen displays for the WAN interface that you selected. (The following figure shows
the WAN2 Advanced Options screen as an example.)
Page 73 / 469
IPv4 and IPv6 Internet and WAN Settings
73
ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308
Figure 46.
4.
Enter the settings as described in the following table:
Table 13.
WAN Advanced Options screen settings
Setting
Description
MTU Size
Make one of the following selections:
Default
Select the
Default
radio button for the normal maximum transmit unit (MTU)
value. For most Ethernet networks, this value is 1500 bytes, or 1492
bytes for
PPPoE connections.
Custom
Select the
Custom
radio button, and enter an MTU value in the Bytes field. For
some ISPs, you might need to reduce the MTU. This is rarely required, and
should not be done unless you are sure that it is necessary for your ISP
connection.
Page 74 / 469
IPv4 and IPv6 Internet and WAN Settings
74
ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308
Speed
In most cases, the VPN firewall can automatically determine the connection speed of the WAN port of the
device (modem, dish, or router) that provides the WAN connection. If you cannot establish an Internet
connection, you might need to manually select the port speed. If you know the Ethernet port speed of the
modem, dish, or router, select it from the drop-down list. Use the half-duplex settings only if the full-duplex
settings do not function correctly.
Select one of the following speeds from the drop-down list:
AutoSense
. Speed autosensing. This is the default setting, which can sense all Ethernet speeds and
duplex modes, including 1000BASE-T speed at full duplex.
10BaseT Half_Duplex
. Ethernet speed at half duplex.
10BaseT Full_Duplex
. Ethernet speed at full duplex.
100BaseT Half_Duplex
. Fast Ethernet speed at half duplex.
100BaseT Full_Duplex
. Fast Ethernet speed at full duplex.
1000BaseT Full_Duplex
. Gigabit Ethernet speed at full duplex.
Router’s MAC Address
Each computer or router on your network has a unique 48-bit local Ethernet address. This is also referred to
as the computer’s Media Access Control (MAC) address. The default is set to Use Default Address.
Make one of the following selections:
Use Default Address
Each computer or router on your network has a unique 32-bit local Ethernet
address. This is also referred to as the computer’s Media Access Control (MAC)
address. To use the VPN firewall’s own MAC address, select the
Use Default
Address
radio button.
Use this computer’s MAC
Address
Select the
Use this computer’s MAC Address
radio button to allow the VPN
firewall to use the MAC address of the computer you are now using to access
the web management interface. This setting is useful if your ISP requires MAC
authentication.
Use this MAC Address
Select the
Use this MAC Address
radio button, and manually enter the MAC
address in the field next to the radio button. You would typically enter the MAC
address that your ISP is requiring for MAC authentication.
Note:
The format for the MAC address is 01:23:45:67:89:AB (numbers
0–9 and either uppercase or lowercase letters A–F). If you enter a MAC
address, the existing entry is overwritten.
Table 13.
WAN Advanced Options screen settings (continued)
Setting
Description
Page 75 / 469
IPv4 and IPv6 Internet and WAN Settings
75
ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308
5.
Click
Apply
to save your changes.
Failure Detection Method
Note:
This is the failure detection method for IPv4 interfaces. For information about failure detection for
IPfv6 interfaces, see
Configure the Failure Detection Method for IPv6 Interfaces
on page
70.
Failure Detection Method
Select a failure detection method from the drop-down list:
WAN DNS
. DNS queries are sent to the DNS server that is configured in
the Domain Name Server (DNS) Servers section of the WAN ISP screen
(see
Manually Configure an IPv4 Internet Connection
on page
34).
Custom DNS
. DNS queries are sent to a DNS server that you need to
specify in the DNS Server fields.
Ping
. Pings are sent to a server with a public IP address that you need to
specify in the IP Address fields. The server should not reject the ping
request and should not consider ping traffic to be abusive.
Note:
DNS queries or pings are sent through the WAN interface that is being
monitored. The retry interval and number of failover attempts determine how
quickly the VPN firewall switches from the primary link to the backup link if the
primary link fails, or when the primary link comes back up, switches back from
the backup link to the primary link.
DNS Server
The IP address of the DNS server.
IP Address
The IP address of the interface that should receive the ping request. The
interface should not reject the ping request and should not consider ping traffic
to be abusive
Retry Interval is
The retry interval in seconds. The DNS query or ping is sent after every retry
interval. The default retry interval is 30 seconds.
Failover after
The number of failover attempts. The primary WAN interface is considered down
after the specified number of queries have failed to elicit a reply. The backup
interface is brought up after this situation has occurred. The failover default is
4
failures.
Upload/Download Settings
These settings rate-limit the traffic that is being forwarded by the VPN firewall.
WAN Connection Type
From the drop-down list, select the type of connection that the VPN firewall uses
to connect to the Internet:
DSL
,
ADLS
,
T1
,
T3
, or
Other
.
WAN Connection Speed
Upload
From the drop-down list, select the maximum upload speed that is provided by
your ISP. You can select from 56 Kbps to 1 Gbps, or you can select
Custom
and
enter the speed in Kbps in the field below the drop-down list.
WAN Connection Speed
Download
From the drop-down list, select the maximum download speed that is provided
by your ISP. You can select from 56 Kbps to 1 Gbps, or you can select
Custom
and enter the speed in Kbps in the field below the drop-down list.
Table 13.
WAN Advanced Options screen settings (continued)
Setting
Description

Rate

3.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top