Network Connections
51
Warning
We strongly recommend leaving network switch
A
as a LAN connection, as this is the
interface through which the CyberGuard SG appliance will attempt to network load a
recovery firmware image in the unlikely event that it fails to boot.
Recovery booting from
an untrusted network poses a security hazard.
SG560, SG565, SG580: Multifunction Ports
The CyberGuard SG560, SG565 and SG580 appliances have generically named
Ethernet ports (ports
A1
,
A2
,
A3
,
A4
and
B
).
By default, switch
A
functions as a regular
LAN switch, with network traffic passing freely between its ports.
Typically, port
B
will be
used as your primary Internet connection.
However, switch
A
’s ports can be configured individually to perform separate functions,
e.g. port
A2
can be a configured as a bridge to a second LAN, port
A3
can be configured
as a DMZ port, and port
A4
can be configured as a failover or load balancing Internet
connection.
These per-port configuration scenarios are accomplished using
VLANs
(virtual local area
networks).
For documentation concerning the advanced use of the VLAN capability of
your CyberGuard SG appliance, refer to the sections entitled
VLANs
and
Port based
VLANs towards
the end of this chapter.
All Other SG Models: Fixed-function Ports
All other CyberGuard SG appliances have specifically labeled ports for specific functions.
The port labeled
LAN
may only perform the functions described in the section entitled
LAN Connection
, the port labeled
Internet
or
WAN
may only perform the functions
described in the section entitled
Internet Connection
.
Note
On SG570 and SG575 models, the
DMZ
port is special in that it may be configured to
connect to a LAN (
LAN Connection
),
a DMZ (
DMZ Connection
)
or as a failover or load-
balancing
Internet link (
Internet Connection
).