Specifications
Advanced Deployment Options
3-17
Deployment Recommendations
Figure 3-11 below shows the recommended deployment setup for the appliance.
FIGURE 3-11. Recommended position of InterScan Gateway Security
Appliance and other network devices in single- or
multi-segment environments
To minimize issues and speedily complete deployment, deploy the appliance:
• Between a firewall that leads to the public network and a router, switch, or hub
that leads to the protected segment of the local area network.
Connect a router, switch, or hub to the INT port, thereby creating a protected
network. Connect the
EXT port to a device that leads to the public network or
Internet.
• Before a proxy server leading to the public network.
If deploying in a multi-segment environment, take note of the following
recommendations:
• Connect the default gateway to the EXT port.
• Use the same default gateway setting for both the appliance and the router that
connects the appliance to the segments.
• Using the Web console, add the static routes for each segment to the appliance.
• Disable the proxy settings from the HTTP URL Filtering screen if traffic is not
passing through the appliance.
Refer to Deployment Issues on page 3-18 to learn about the known deployment issues
in this release. For details about single and multi-segment deployment topologies, see
Deploying in a Single Network Segment on page 3-4 and Deploying in a Network with
Multiple Segments on page 3-5.
Client
Switch
Proxy server
Router
Internet