User guide
Chapter 3: Getting Started
28 WatchGuard Firebox System
Characteristics of a drop-in configuration:
• A single network that is not subdivided into smaller networks or
subnetted.
• The Firebox performs proxy ARP, a technique in which one host
answers Address Resolution Protocol requests for machines behind
that Firebox that cannot hear the broadcasts. The Trusted interface
ARP address replaces the router’s ARP address.
• The Firebox can be placed in a network without changing default
gateways on the Trusted hosts. This is because the Firebox answers
for the router, even though the router cannot hear the Trusted host’s
ARP requests.
• All Trusted computers must have their ARP caches flushed.
• The majority of a LAN resides on the Trusted interface by creating a
secondary network for the LAN.
The benefit of a drop-in configuration is that you don’t have to
reconfigure machines already on a public network with private IP
addresses. The drawback is that it is generally harder to manage and is
more prone to network problems.