Selecting a Firewall Configuration Mode
before installing the watchguard firebox system, you must decide how to incorporate the firebox into your network. this decision determines how you will set up the three firebox interfaces–external, trusted, and optional.
external interface
connects to the external network (typically the internet) that presents the security threat.
trusted interface
connects to the private lan or internal network that you want protected.
optional interface
connects to the dmz (demilitarized zone) or mixed trust area of your network. computers on the optional interface contain content you do not mind sharing with the rest of the world.
common applications housed on this interface are web, email, and ftp servers.
to decide how to incorporate the firebox into your network, select the configuration mode that most closely reflects your existing network. you must select one of two possible modes: routed or drop-in configuration.