How to config NSF-3100A-1 route mode with 2 IP Segment?

Yuniar Ashurin Lv1Posted Apr-21-2025 16:27

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x

fuadmahbubun has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Hi, Based on your picture here some example configuration

Go to Network >> Interface

select eth1
choose type : Layer 3, check wan Attribute
insert static ip address : 203.87.81.216/30 gateway 203.87.81.215
select zone, (create if there is no current zone ) : internet, then Save

select eth2
choose Type : Layer 3
insert static ip address : 192.168.3.1/24
select zone : LAN1, then Save

Select eth3

Choose Type : Layer 3
insert static ip address : 192.168.4.1/24
select zone : LAN2, then Save

Go to Network >> Routes
select static route then add
add dst address : 0.0.0.0/0.0.0.0 gateway 203.87.81.215

Go To Policy >> NAT

add source NAT
src zone : LAN1, LAN2
src address : LAN1, LAN2

dst zone : Internet
dst address all

translate src ip to outbond interface, then save.

Go To Policy >> access Control
select  Application Control

Add
src zone : LAN1, LAN2
src address : LAN1, LAN2

dst zone : Internet
dst address all
action Allow

Then Save.
Is this answer helpful?
AR Lv2Posted Apr-21-2025 17:06
  
Configure NSF-3100A-1 in Route Mode with 2 IP Segments:
Set Route Mode:

Go to System > Network > Working Mode

Select Route Mode

Assign IPs to Interfaces:

eth0: 192.168.1.1/24

eth1: 192.168.2.1/24

Set Security Policy:

Allow traffic between the two zones/interfaces.

Test Connectivity:

Ping between devices in the two networks.
fuadmahbubun Lv2Posted Apr-21-2025 17:24
  
hi, please refer to this documents.
SANGFOR_NSF_V8.0.85_Associate_2024_03_Deployment page 7.

fuadmahbubun Lv2Posted Apr-21-2025 17:39
  
Last edited by fuadmahbubun 2025-Apr-21 17:40.

Hi, please refer to these documents for deployment and network configuration.
sangfor knowledgebase
make sure you have configured zone for every interface to allow data packet.

here some examples based on your picture:
interface 1 :  type access, ip address 203.87.81.216/30 gateway 203.87.81.215/30 zone : internet
interface 2 : type access, ip address 192.168.3.1/24 zone : lan1
interface 3 : type access, ip address 192.168.4.1/24 zone : lan 2

go to network >> routing. add dst address 0.0.0.0/0 gateway 203.87.81.215
go to network policy
create NAT for data access internet from lan 1 to internet, and from lan 2 to internet.
create network policy to allow data form lan 1 to lan 2 and from lan 2 to lan 1.
fuadmahbubun Lv2Posted Apr-21-2025 17:54
  
Go to Network >> interfaces
setup for interfaces based on your picture :
eth1 : select type : Layer 3 wan Attribut Yes,  ip address : 203.87.81.216/30 gateway 203.87.81.215 select zone : internet
eth2 : select type : layer 3, ip address : 192.168.3.1/24 zone : LAN1
eth3 : select type : layer 3, ip address : 192.168.4.1/24 zone: LAN2

select menu Routing, add route 0.0.0.0/0 gateway 203.87.81.215

Go to Policy >> NAT
create source nat from your LAN to Internet

Go To Policy >> Access Control >> Application Control
click add, then create the rule for data packet rom lan 1 and lan 2 to internet.
create rule for data packet from lan1 to lan2 and form lan2 to lan1.

For complete guidance please refer to sangfor knowlede base. here
Newbie517762 Lv5Posted Apr-22-2025 08:58
  
HiHi,

Pls find below for the NSF route mode configuration ideas:
Also, pls find the attachment file for your Ref.

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
fuadmahbubun Lv2Posted Apr-22-2025 09:05
  
Hi, Based on your picture here some example configuration

Go to Network >> Interface

select eth1
choose type : Layer 3, check wan Attribute
insert static ip address : 203.87.81.216/30 gateway 203.87.81.215
select zone, (create if there is no current zone ) : internet, then Save

select eth2
choose Type : Layer 3
insert static ip address : 192.168.3.1/24
select zone : LAN1, then Save

Select eth3

Choose Type : Layer 3
insert static ip address : 192.168.4.1/24
select zone : LAN2, then Save

Go to Network >> Routes
select static route then add
add dst address : 0.0.0.0/0.0.0.0 gateway 203.87.81.215

Go To Policy >> NAT

add source NAT
src zone : LAN1, LAN2
src address : LAN1, LAN2

dst zone : Internet
dst address all

translate src ip to outbond interface, then save.

Go To Policy >> access Control
select  Application Control

Add
src zone : LAN1, LAN2
src address : LAN1, LAN2

dst zone : Internet
dst address all
action Allow

Then Save.
Ayra Posted Apr-22-2025 11:15
  
Configure the NSF-3100A-1 in Route Mode using two IP segments:  Set Route Mode:  Go to System > Network > Working Mode.  Select Route Mode.  Assign IP addresses to Interfaces:  eth0: 192.168.1.1/24  eth1: 192.168.2.1/24  Set a Security Policy:  Allow communication between the two zones/interfaces.  Check Connectivity:  Ping between devices on the two networks.
Newbie578211 Posted Apr-22-2025 12:47
  
Set Route Mode:
Go to System > Network > Working Mode → select Route Mode → Save.

Assign IPs:

eth0: 192.168.1.1/24

eth1: 192.168.2.1/24

Create Security Policy:
Allow traffic between eth0 zone and eth1 zone (both directions).

Check Connectivity:
Ping between devices on 192.168.1.x and 192.168.2.x networks.
Newbie314031 Lv1Posted Apr-22-2025 13:01
  
Last edited by Newbie314031 2025-May-05 12:16.

Configure the NSF-3100A-1 in Route Mode with two IP segments:

1. Set Route Mode: Go to System > Network > Working Mode and select Route Mode.
2. Assign IPs: eth0: 192.168.1.1/24, eth1: 192.168.2.1/24.head basketball
3. Set a Security Policy: Allow communication between zones/interfaces.
4. Check Connectivity: Ping devices on both networks.

I Can Help:

Change

Moderator on This Board

1
148
3

Started Topics

Followers

Follow

917
183
94

Started Topics

Followers

Follow

Board Leaders