FireBrick Route Guide
Routes
The FireBrick has to decide where to send traffic. This is done using routing rules. The rules are considered in order and the first appropriate matching route is applied. The routing list includes the subnets and the default gateway. The default gateway is always at the end, but the subnets can be moved to allow routes to be considered before or after the normal routes to subnets.
| Name | Allows you to give a name to this rule |
| Security | Sets the security level of this rule and so defines who can view or edit the users details |
| Profile | Defines the profile when this rule applies. |
| Source | This allows you to specify one or more source interfaces from which the traffic may come |
| Send to | This allows you to say what interface the traffic will be sent |
| Gateway IP | The gateway to use on the specific interface. Blank if ARP is to be used. |
| Weight | For advanced use |
| NAT | Specifies that traffic is to be NATed when using this route |
| Proxy ARP | For advanced use |
| Source ports | This allows a range of source ports to be specified. Applicable to TCP and UDP. Normally blank meaning any. |
| Target ports | This allows a range of target ports to be specifiied. Applicable to TCP and UDP. Typically just one port for the specific protocol, e.g. 80 for WWW |
| Protocol | This allows the specific protocol to be specified, or Any. |
| Port group | Instead of using a source port range, target port range and protocol, then a named port group can be selected. |
| Source IP range | Allows the range of source IPs to be specified, or blank for any. |
| Source IP group | Instead of an IP range, a named IP group can be selected. |
| Target IP range | Allows the range of target IPs to be specified, or blank for any. |
| Target IP group | Instead of an IP range, a named IP group can be selected. |
Technical Reference
- Stealth traffic already has a target MAC address on the other side of the FireBrick, and as such the FireBrick already knows the interface and target MAC to use. Stealth traffic is not subnet to the routing table.
- Some traffic has a partial route already, such as address mapped traffic which may be to LAN but not say which subnet, and return traffic for any sessions which should be via the interface on which it arrived. In such cases routes are only considered if they match the target interface correctly.
- Any route that sets an interface with a subnet, but for which a gateway is not defined will use the DHCP gateway defined for the subnet if specified. This is used in such cases before considering the default route. If there is not gateway defined, and the default is not the same general interface, then an ARP is done for the target IP, even if outside the known IPs for a subnet.
- Proxy ARP is ignored on routes with protocol selection or group, as ARPs do not have an IP protocol.
- See Weighted rules for details on how to use the Weight option. This applies only with the bonding feature.
- If an explicit route is picked, then the NAT flag indicates if NAT applies or not. If a subnet route or the default route is picked then NAT is set based on the source IP/subnet being set for NAT.
- If a route is set for target Any, then the NAT flag may be set at that point, but the routing continues until an explicit target interface is found
- The proxy ARP setting causes the FireBrick to answer ARPs on the source interfaces for the IP range/group specified as the target
- Routing is done before filtering as filters operate on the apparent target interface (which is decided by routing)
- Routing is also done before any traffic shaping or address mapping wich are done after filtering. Address mapping may however cause routing to be done again if the addresses or interfaces are charged.
- A more detail description of routing is shown here.