Can I configure MFE for Transparent mode, when internal_network have two interfaces.
That mean, I use three interfaces in Brigde mode.
MFE device in this case : S1104.
I believed that three interfaces in a bridge were possible, but just to confirm, I searched and found this in the 8.3.2 Product Guide:
In transparent (bridged) mode, two or more firewall interfaces are connected inside a single network and bridged to form a transparent interface.
So yes it is possible.
Thanks for reply,
I tried configure three interface in a bridge mode, save OK.
However, there is only one interface in internal_network working and connect to external_network.
The version of My firewall is 8.3.1. I will upgraded to 8.3.2 and try again. I hope that it doing well
I tried with 8.3.2. it's not work.
Default, in transparent (bridged) mode, members of the bridge group are the following interface:
I can choose to more than interfaces (eg: internal_02, internal_03) in the bridge group. However, only INTERNAL_NETWORK interface which is connected to EXTERNAL (internet zone).
I have captured my screen when I switching from INTERNAL_NETWORK interface to INTERNAL_02.
The policy is allow All.
You can use these commands to help you troubleshoot:
-- Shows you the zone numbers for each zone name. The next commands only display the zone number from 'region.'
$> ifconfig bridge0 addr
-- Lists the addresses learned by the bridge and shows which interface in the bridge saw that IP/MAC combination
$> ifconfig bridge0 flush
-- Flushes all the learned addressses
$> ifconfig bridge0 maxaddr [size]
-- The default size is 100 entries in the bridge table. You may or may not have to increase this someday.
$> arp -an
-- Shows your arp table
$> route -n get [IP address]
-- Shows which interface a packet would go if it is destined for [IP address]
You should call into Support if you do not know how to use all of these commands, along with tcpdump, to troubleshoot the connection. Unless you are at the latest version of code, the audit will not be helpful for you here (the latest versions added audits to help diagnosing bridge issues).