User guide

Chapter 3: Getting Started
28 WatchGuard Firebox System
Characteristics of a drop-in configuration:
A single network that is not subdivided into smaller networks or
subnetted.
The Firebox performs proxy ARP, a technique in which one host
answers Address Resolution Protocol requests for machines behind
that Firebox that cannot hear the broadcasts. The Trusted interface
ARP address replaces the router’s ARP address.
The Firebox can be placed in a network without changing default
gateways on the Trusted hosts. This is because the Firebox answers
for the router, even though the router cannot hear the Trusted host’s
ARP requests.
All Trusted computers must have their ARP caches flushed.
The majority of a LAN resides on the Trusted interface by creating a
secondary network for the LAN.
The benefit of a drop-in configuration is that you don’t have to
reconfigure machines already on a public network with private IP
addresses. The drawback is that it is generally harder to manage and is
more prone to network problems.