Quick Reference Guide

Table Of Contents
34 | Chapter 3: LAN Configuration
ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336Gv2 Reference Manual
commas and without any blank spaces. For most users, the search base is a variation
of the domain name. For example, if your domain is yourcompany.com, your search
base dn might be as follows: dc=yourcompany,dc=com.
port. Specifies the port number that the LDAP server is using. Leave this field blank
for the default port.
4. In the Advanced Settings section, configure the following settings:
Enable DNS Proxy. If the DNS proxy is enabled (which is the default setting), the
DHCP server will provide the VPN firewall’s LAN IP address as the DNS server for
address name resolution. If this box is unchecked, the DHCP server will provide the
ISP’s DNS server IP addresses. The VPN firewall will still service DNS requests sent
to its LAN IP address unless you disable DNS Proxy in the network storage settings
(see “Attack Checks” on page 54).
Enable ARP Broadcast. If ARP broadcast is enabled (which is the default setting),
the Address Resolution Protocol (ARP) is broadcasted on the LAN so that IP
addresses can be mapped to physical addresses (that is, MAC addresses).
5. Click Apply to save your settings.
Note: Once you have completed the LAN setup, all outbound traffic is
allowed and all inbound traffic is discarded. To change these default
traffic rules, refer to Chapter 4,“Firewall Protection and Content
Filtering".
Managing Groups and Hosts (LAN Groups)
The Known PCs and Devices table on the LAN Groups screen contains a list of all known
PCs and network devices that are assigned dynamic IP addresses by the VPN firewall, or
have been discovered by other means. Collectively, these entries make up the LAN Groups
Database.
The LAN Groups Database is updated by these methods:
DHCP Client Requests. By default, the DHCP server in this VPN firewall is enabled, and
will accept and respond to DHCP client requests from PCs and other network devices.
These requests also generate an entry in the LAN Groups Database. Because of this,
leaving the DHCP server feature (on the LAN screen) enabled is strongly recommended.
Scanning the Network. The local network is scanned using ARP requests. The ARP
scan will detect active devices that are not DHCP clients. However, sometimes the name
of the PC or device cannot be accurately determined, and will appear in the database as
Unknown.
Manual Entry. You can manually enter information about a network device.