Specifications

Advanced Deployment Options
3-17
Deployment Recommendations
Figure 3-11 below shows the recommended deployment setup for the appliance.
FIGURE 3-11. Recommended position of InterScan Gateway Security
Appliance and other network devices in single- or
multi-segment environments
To minimize issues and speedily complete deployment, deploy the appliance:
Between a firewall that leads to the public network and a router, switch, or hub
that leads to the protected segment of the local area network.
Connect a router, switch, or hub to the INT port, thereby creating a protected
network. Connect the
EXT port to a device that leads to the public network or
Internet.
Before a proxy server leading to the public network.
If deploying in a multi-segment environment, take note of the following
recommendations:
Connect the default gateway to the EXT port.
Use the same default gateway setting for both the appliance and the router that
connects the appliance to the segments.
Using the Web console, add the static routes for each segment to the appliance.
Disable the proxy settings from the HTTP URL Filtering screen if traffic is not
passing through the appliance.
Refer to Deployment Issues on page 3-18 to learn about the known deployment issues
in this release. For details about single and multi-segment deployment topologies, see
Deploying in a Single Network Segment on page 3-4 and Deploying in a Network with
Multiple Segments on page 3-5.
Client
Switch
Proxy server
Router
Internet