SonicOS 7 System

Configuring an Interface for Wire Mode

To configure an interface for Wire Mode

  1. Navigate to NETWORK | System > Interfaces.
  2. Click the Configure icon for the interface you want to configure for Wire Mode. The Edit Interface dialog displays.
  3. From Zone, select any zone type except WLAN.
  4. From Mode / IP Assignment, to configure the Interface for:
    • Tap mode, select Tap Mode (1-Port Tap).
    • Wire Mode, select Wire Mode (2-Port Wire).
  5. From Wire Mode Type, select the appropriate mode:
    • Bypass (via Internal Switch/Relay)
    • Inspect (Passive DPI of Mirrored Traffic)
    • Secure (Active DPI of Inline Traffic)
  6. From Paired Interface, select the interface that connects to the upstream firewall. The paired interfaces must be of the same type (two 1 GB interfaces or two 10 GB interfaces).

    Only unassigned interfaces are available from Paired Interface. To make an interface unassigned, click its Configure, and from Zone, select Unassigned.

  7. Wire Mode can be configured on any zone (except wireless zones). Wire Mode is a simplified form of Layer 2 Bridge Mode, and is configured as a pair of interfaces. In Wire Mode, the destination zone is the Paired Interface Zone. Access rules are applied to the Wire Mode pair based on the direction of traffic between the source Zone and its Paired Interface Zone. For example, if the source Zone is WAN and the Paired Interface Zone is LAN, then WAN to LAN and LAN to WAN rules are applied, depending on the direction of the traffic.

  8. In Wire Mode, you can Disable Stateful Inspection. When Disable Stateful Inspection is selected, Stateful Packet Inspection (SPI) is turned off. When Disable Stateful Inspection is not selected, new connections can be established without enforcing a 3-way TCP handshake. Disable Stateful Inspection must be selected if asymmetrical routes are deployed.

  9. In Wire Mode, you can Enable Link State Propagation, which propagates the link status of an interface to its paired interface. If an interface goes down, its paired interface is forced down to mirror the link status of the first interface. Both interfaces in a Wire Mode pair always have the same link status.

  10. When Inspect Mode is selected, the Restrict analysis at resource limit option is displayed. It is disabled by default. When this option is enabled, the appliance scans the maximum number of packets it can process. The remaining packets are allowed to pass without inspection. When this option is disabled, traffic is throttled in the flow of traffic exceeds the firewalls inspection ability.

    Disabling the Restrict analysis at resource limit option reduces throughput if the rate of traffic exceeds the appliance’s ability to scan all traffic.

  11. Click OK.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden