After the Edge Firewall add-on is enabled, the Site Configuration > LAN Settings tab will need to be configured as needed for the local environment.
NAT Firewall → Allows a single block of RFC1918 addresses to be assigned to the LAN and will use a single /32 public IP to NAT all traffic from the LAN to the internet. The LAN network for assigning private IP’s to LAN clients can be modified in size, and can be configured to act as a DHCP server for LAN clients.
NAT Firewall + VLANs → Allows multiple blocks of RFC1918 addresses to be assigned to the LAN and use VLAN marking to separate traffic. This will still use a single /32 public IP to NAT all traffic from the LAN to the internet. The VLAN networks can then be modified in size and can be configured to act as a DHCP server for LAN clients across all VLANs.
Each VLAN will need to be assigned a VLAN ID, a VLAN name, Description, Port, Subnet (in CIDR format) and a Local address (gateway)
What type of VLAN implementation does Bigleaf support?
Feature support for all VLANs: DHCP server, NAT, port forwarding, diagnostic tests.
Firewall-protected bidirectional forwarding:
VLAN to internet
VLAN to VLAN
VLAN to IPSEC
Guest WiFi can talk to the internet only; no VLAN support.
WiFi only available on Edge 800W device model
IPv4 only as the next protocol in the VLAN header.
QoS classification and rewrite via the IP QoS header, not the VLAN p-bit field.
Standard IEEE 802.1q VLANs.
Single-tagged VLANs, not stacked VLANs.
STP is not supported on the Bigleaf CPE; customers may run STP on their own switches.
VLAN IDs from 2 to 4094, except 200 (reserved due to high availability sites).
VLAN trunk ports only, not VLAN access ports.
Primary WiFi can be configured as though it is a VLAN access port.
Guest WiFi has no VLAN support.
WiFi only available on Edge 800W device model
Comments
0 comments
Article is closed for comments.