27
Chapter 4 - Firewall Software
Configuration 3 - New Dual-LAN with T1 DSU
The final typical configuration adds Internet services to existing LAN users. With this
configuration, the private LAN (LAN 1) is secured by the firewall while the Internet Services
Network is outside the firewall allowing Internet users to access the public LAN (LAN 2)
resources, such as the Web, FTP, etc. servers. The Internet connection is provided with a T1
DSU connected to the RS232 connection on the back of the unit.
MTPSR1-120 Firewall
IP Address 192.168.0.101
Mask 255.255.255.0
Internet
Novell Server
IP Address
192.168.0.102
Windows NT Server
IP Address
192.168.0.103
Mail Server
IP Address
192.168.0.104
Workstation
IP Address
192.168.0.105
Workstation
IP Address
192.168.0.106
Workstation
IP Address
192.168.0.107
HUB
TM
TM
LAN 1
Private
LAN 2
Public
Video Server
IP Address
204.26.12.40
Web Server
IP Address
204.26.12.20
FTP Server
IP Address
204.26.12.30
HUB
Private LAN
Internet Services
Network
Internet LAN
IP address
204.26.12.10
WAN Port
T1 DSU
Figure 4-3. New Dual-LAN with T1 DSU Configuration
In the configuration shown in Figure 4-3, the ProxyServer is connected to the private LAN via the
LAN 1 connection of the back of the ProxyServer. The Internet Services Network, or public LAN,
is connected to the LAN 2 connector on the back of the unit. Connection to the Internet is then
provided by a T1 DSU connected to the RS232/V.35 connector on the back of the unit.
During the loading of the Firewall software, the Secured LAN Port Parameters group (in the IP
Setup dialog box) was configured to include an unregistered IP Address of 192.168.0.101 and
default Net Mask of 255.255.255.0 for the private LAN (LAN 1).