09.07.2015 Views

Firebox SSL VPN Gateway Administration Guide - WatchGuard ...

Firebox SSL VPN Gateway Administration Guide - WatchGuard ...

Firebox SSL VPN Gateway Administration Guide - WatchGuard ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Firebox</strong> <strong>SSL</strong> OverviewDeployment OptionsThe <strong>Firebox</strong> <strong>SSL</strong> Quick Start describes how to install the <strong>Firebox</strong><strong>SSL</strong> with a firewall, the most common configuration. You canalso connect the <strong>Firebox</strong> <strong>SSL</strong> to other devices such as a serverload balancer or router.Connecting to a Server Load BalancerYou can connect one or more <strong>Firebox</strong> <strong>SSL</strong>s to a server load balancer.Characteristics of this configuration include the following:• Incoming web traffic is intercepted by the server loadbalancer and load balanced between the <strong>Firebox</strong> <strong>SSL</strong>s (ifmore than one <strong>Firebox</strong> <strong>SSL</strong> is in use).• For optimal performance, the server load balancer isconfigured with a virtual IP (VIP). The VIP is used by the<strong>Firebox</strong> <strong>SSL</strong> when reestablishing connection to the serverload balancer.• The <strong>Firebox</strong> <strong>SSL</strong> External Public Address is the externalfacing(public) VIP address of the server load balancer. The<strong>Firebox</strong> <strong>SSL</strong> modifies all requests to include the ExternalPublic Address. The External Public Address ensures that theredirected client returns to the <strong>Firebox</strong> <strong>SSL</strong> it firstencountered, providing session stickiness. The associationbetween a particular request and the <strong>Firebox</strong> <strong>SSL</strong> is brokenonly when the client makes a new connection.To establish the physical connection, connect the <strong>Firebox</strong> <strong>SSL</strong>eth0 interface to the internal network. Use the <strong>Firebox</strong> <strong>SSL</strong><strong>Administration</strong> Tool to configure network settings. Specify theIP address of the server load balancer as the Default <strong>Gateway</strong>setting on the Networking > General Networking tab.16 <strong>Firebox</strong> <strong>SSL</strong> <strong>VPN</strong> <strong>Gateway</strong> <strong>Administration</strong> <strong>Guide</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!