SonicOS Enhanced firmware versions 4.0 and higher includes L2 (Layer 2) Bridge Mode, a new method of unobtrusively integrating a SonicWall security appliance into any Ethernet network. L2 Bridge Mode is ostensibly similar to SonicOS Enhanced Transparent Mode in that it enables a SonicWall security appliance to share a common subnet across two interfaces, and to perform Stateful and deep-packet inspection on all traversing IP traffic, but it is functionally more versatile.
In particular, L2 Bridge Mode employs a secure learning bridge architecture, enabling it to pass and inspect traffic types that cannot be handled by many other methods of transparent security appliance integration. Using L2 Bridge Mode, a SonicWall security appliance can be non-disruptively added to any Ethernet network to provide in-line deep-packet inspection for all traversing IPv4 TCP and UDP traffic. In this scenario the SonicWall UTM appliance is not used for security enforcement, but instead for bidirectional scanning, blocking viruses and spyware, and stopping intrusion attempts.
Unlike other transparent solutions, L2 Bridge Mode can pass all traffic types, including IEEE 802.1Q VLANs (on SonicWall NSA appliances), Spanning Tree Protocol, multicast, broadcast, and IPv6, ensuring that all network communications will continue uninterrupted.
This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.
Configuring the Primary Bridge Interface
Choose an interface to act as the Primary Bridge Interface. In this example, we will use X2 interface (WAN). Follow below steps to configure X2 interface as WAN.
NOTE: The Primary Bridge Interface must have a Static IP assignment.
Configuring the Secondary Bridge Interface
Choose an interface to act as the Secondary Bridge Interface. In this example, we will use X0 (automatically assigned to the LAN).
8. You may optionally enable the Block all non-IPv4 traffic setting to prevent the L2 bridge from passing non- IPv4 traffic. VLAN Filtering (on SonicWall NSA series appliances).
9. The Network | Interfaces page displays the updated configuration: You may now apply security services to the appropriate zones, as desired. In this example, they should be applied to the LAN, WAN, or both zones.
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Configuring the Primary Bridge Interface
Choose an interface to act as the Primary Bridge Interface. In this example, we will use X2 interface (WAN). Follow below steps to configure X2 interface as WAN.
Configuring the Secondary Bridge Interface
Choose an interface to act as the Secondary Bridge Interface. In this example, we will use X0 (automatically assigned to the LAN).
The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.
Configuring the Primary Bridge Interface
Choose an interface to act as the Primary Bridge Interface. In this example, we will use X1 (automatically assigned to the Primary WAN): Network | Interfaces
EXAMPLE: 192.168.160.50
NOTE: The Primary Bridge Interface must have a Static IP assignment.
Configuring the Secondary Bridge Interface
Choose an interface to act as the Secondary Bridge Interface. In this example, we will use X0 (automatically assigned to the LAN): Network | Interfaces.
NOTE: The Network | Interfaces page displays the updated configuration: You may now apply security services to the appropriate zones, as desired. In this example, they should be applied to the LAN, WAN, or both zones.