Solved

Where to put my firewall

Posted on 2006-07-14
6
318 Views
Last Modified: 2013-11-16
I just got a new firewall "WatchGuard Firebox X700" and this is the first Firewall i have ever seen and used. Yes i am a newbie still. Anyways i am trying to figure out where exactlly where to put it at in my network. The following is how my network is.


Earthlink Netopia 4622 T1 Router "Running Nat" "Numbered IP Address"

48 Port Netgear Gigabit Switch


The T1 router plugs into the Switch and then all the users plug into the switch as well.


Thanks for the help

0
Comment
Question by:hcl1
  • 3
  • 3
6 Comments
 
LVL 10

Assisted Solution

by:naveedb
naveedb earned 500 total points
ID: 17112512
It should go between the T-1 router and Switch. If you want, you can move the NAT functionality to the WatchGuard to avoid duplicate NAT translations.
0
 

Author Comment

by:hcl1
ID: 17112818
Thanks for the feed back.....On my firewall box i have an External port and then Ports 1 Thru 5........ Should i plug in the router in the external and then a cable in port 1 to the switch?



Do you think earthlink will have any problems with takiing NAT off? I know i had major problems when i first got the T1 line becasue they didnt have NAT on our what they called "Numbered IP Address" and they had to go back and change my IP address.
0
 
LVL 10

Accepted Solution

by:
naveedb earned 500 total points
ID: 17113120
Thanks for the feed back.....On my firewall box i have an External port and then Ports 1 Thru 5........ Should i plug in the router in the external and then a cable in port 1 to the switch?

Yes, you will be expandin the ports on your firewall by connecting it to the switch. You may need to cross-over cable if you don't have a port that can connect two switches together MDI/MDIX.

Do you think earthlink will have any problems with takiing NAT off? I know i had major problems when i first got the T1 line becasue they didnt have NAT on our what they called "Numbered IP Address" and they had to go back and change my IP address.
 
I am not sure what the issue was originally. But give it a try, I have used this config few times without any issues. Do you have a single IP Address or a usable subnet of Public IP Addresses. If you have a single IP Address, then you may need to configure the T-1 router in a bridge mode if you disable NAT.
0
Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 

Author Comment

by:hcl1
ID: 17113157
Thanks again......Earthlink provides us with a static WAN IP address and then a block of Useable IP address as well. We dont own any of them. Should i still be good?
0
 
LVL 10

Assisted Solution

by:naveedb
naveedb earned 500 total points
ID: 17114061
Yes, you should be fine. Assign one IP address from the block to the WatchGaurd and you should be good to go.
0
 

Author Comment

by:hcl1
ID: 17114931
Thanks for all the info... I am going to give it a try next weekend because i have alot to put together first and plus nobody will be there on the weekend.
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now