
Similarly, you’ll need to specify the reverse route: let’s say you only want to route packets to vlan1 from ports
configured for vlan2
if they originated on subnet
sn03. To accomplish this, you’ll need to specifically add that
VLAN/subnet combination to the permitted VLAN list for vlan2:
eqcli > vlan vlan2 subnet sn03 permit vlan1
Source IP Address for Outbound Packets
When Equalizer originates connections to other hosts (for example, when Equalizer sends out probes, queries an
NTP or DNS server, etc.), the source IP address used in the outbound packets will be the IP address for the VLAN
with the def_src_addr flag set. There can be only one VLAN with this flag set.
Note - The above means of determining the IP address to use for Equalizer originated connections applies to the
Beta product only. The final EQ/OS release will use a different mechanism.
Subnet Routes and Global Default Route
Each subnet has a complete routing table. There is no explicit global default route setting that applies to all
subnets. To configure a global default route, you must define the same default route on all subnets.
190
Copyright © 2013 Coyote Point Systems. A subsidiary of Fortinet, Inc.
Comentários a estes Manuais