F3215-HP Load Balancing Module Security Configuration Guide-6PW101

193
Figure 97 Network diagram
Configuring the LB module
1. Assign IP addresses for the interfaces and then add interface GigabitEthernet 0/1 to zone Untrust,
and GigabitEthernet 0/2 to zone Trust. (Details not shown.)
2. Set the TCP proxy mode to bidirectional and enable TCP proxy for zone Untrust:
a. From the navigation tree, select Security > Intrusion Detection > TCP Proxy Configuration.
Figure 98 Selecting the bidirectional mode and enabling TCP proxy for zone Untrust
b. Select Bidirection for the global setting, and click Apply.
c. In the Zone Configuration area, click Enable for the Untrust zone.
3. Add an IP address entry manually for protection:
a. From the navigation tree, select Security > Intrusion Detection >Protected IP Configuration.
b. Click Add.
c. Enter 20.0.0.10 in the Protected IP Address field.
d. Click Apply.