Connecting a Device to a Network
Connecting a Device to an Untrusted Network
An SSG 20 device provides firewall and general security for networks when it is
placed between internal networks and the untrusted network. This section
describes the following:
Connecting a Device to an Untrusted Network
Connecting a Device to an Internal Network or a Workstation
You can connect your SSG 20 device to an untrusted network in one of the following
ways:
Ethernet Ports
Serial (AUX/Console) Ports
Connecting Mini PIMs to an Untrusted Network
Figure 10 shows the SSG 20 with basic network cabling connections with two blank
mini-PIMs and the 10/100 Ethernet ports cabled as follows:
The port labeled 0/0 (ethernet0/0 interface) is connected to the untrust
network.
The port labeled 0/1 (ethernet0/1 interface) is connected to a workstation in the
DMZ security zone.
The port labeled 0/3 (bgroup0 interface) is connected to a workstation in the
Trust security zone.
The Console port is connected to a serial terminal for management access.
Figure 10: Basic Networking Example
1
2
SSG 20
8 0 2 .1 1 a
POWER
PI M 1
STATUS
PI M 2
b /g
WL AN
AUX
Console
Untrust
Zone
L I NK
10 /100
0 /0
10/100
0 /0
10/100
0/ 0
10 /100
0/ 0
10 /100
AUX
0 / 0
Trust
DMZ
Zone
Connecting a Device to a Network
23